JWT vs Session
Session
JWT
signature = Hash( data, secret );
HMACSHA256(
base64UrlEncode(header) + "." +
base64UrlEncode(payload),
secret)Claim

Refresh Token


Last updated
signature = Hash( data, secret );
HMACSHA256(
base64UrlEncode(header) + "." +
base64UrlEncode(payload),
secret)


Last updated
{
"sub": "1234567890",
"name": "John Doe",
"admin": true
}