What is a JWT and what are its parts?
Assesses fundamental understanding of Authentication & Authorization conventions, runtime behavior, and memory/performance considerations.
Hiring managers look for precision, avoidance of ambiguous jargon, and ability to explain trade-offs under real production conditions.
A JSON Web Token is a compact, URL-safe token with three base64url parts separated by dots: header, payload and signature.
eyJhbGciOiJIUzI1NiJ9 . eyJzdWIiOiI0MiJ9 . signature
header payload signature
The header names the signing algorithm and type. The payload holds claims such as iss (issuer), sub (subject), aud (audience), exp (expiry), iat, nbf and custom claims like roles. The signature protects integrity: anyone can decode the payload, so never put secrets in it.
Key points: a JWT is signed, not encrypted (JWE is the encrypted variant). Verification must check the signature with the expected algorithm and validate exp, nbf, iss and aud. Because the server trusts the token without a lookup, revocation requires short lifetimes plus a denylist or a version claim. Never trust a payload you have not verified.
Candidate Response Strategy & Interview Tips
- Start with a concise one-sentence summary: Deliver a direct, confident answer first before expanding into nuances.
- Demonstrate real-world trade-offs: Discuss where this approach excels and when you would avoid it in production systems.
- Discuss complexity & edge cases: Proactively explain time/space complexity or boundary conditions (null values, scale limits).
- Prepare for interviewer follow-ups: Technical hiring panels frequently probe deeper into concurrency, backward compatibility, or alternative libraries.