iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Generate a JWT by deciding which claims the receiving application needs, choosing an approved signing or encryption method and matching key, then using a maintained JWT library to create its compact representation. A signed JWT protects its contents against tampering but does not conceal them. The receiving application must independently verify the token and validate the claims it relies on.
What a JWT contains
A JSON Web Token (JWT) is a compact, URL-safe representation of claims: statements about a subject or other information the issuer wants to convey. A JWT is carried in a JSON Web Signature (JWS) structure, a JSON Web Encryption (JWE) structure, or both. In compact serialization, the encoded parts are separated by periods. The format and its claims are defined by RFC 7519.
A signed JWT is not encrypted by default. Anyone who obtains a typical signed token can read its payload, even though they cannot alter it without detection. Do not put passwords, private keys, or other confidential data in a merely signed token. Use JWE when the application requires confidentiality and its profile supports encrypted tokens.
Choose the claims and protection
Include only claims the application needs
Claims are the information the issuer puts into the token and the verifier may rely on. Common registered claims include iss (issuer), sub (subject), aud (audience), exp (expiration time), nbf (not before), iat (issued at), and jti (JWT ID). The IANA JWT Claims Registry lists registered claim names and their references.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
These registered claims are not all mandatory for every JWT. The application profile must define which claims are required, what their values mean, and what makes a token acceptable. For example, if the issuer serves multiple applications, specify the intended audience and require the verifier to check it.
Select signing or encryption
For a JWS, the claims are signed or protected with a message authentication code (MAC), providing integrity and authenticity under the chosen key arrangement. For a JWE, the claims are encrypted. Choose an algorithm and key type that the application’s security policy and receiving implementation support. Keep each key bound to one algorithm, as recommended by RFC 8725, JSON Web Token Best Current Practices.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Generate the token with a library
- Define the token profile. Agree on the issuer, subject, intended audience, expiry, and any application-specific claims. Add only the information needed by the receiving service.
- Choose the operation and key. Decide whether the application needs a JWS or JWE, then select a supported algorithm and suitable key. Store signing or encryption keys in the application’s approved secret or key-management system, not in source code or a token payload.
- Build the claims as UTF-8 JSON. Set the relevant JOSE header parameters, including the algorithm declaration required for the selected operation.
- Use a JWT library for your language. Have it create the JWS or JWE compact representation rather than assembling encoded segments or cryptographic operations by hand. For Python, the official PyJWT documentation describes a library for encoding and decoding JWTs. For Java, consult the JJWT project documentation, which describes its Java implementation and key-strength checks. Confirm the current documentation and version for your stack.
- Deliver it through the intended channel. Treat the resulting token as a credential if it grants access or authority. Keep it out of logs and other places where unintended parties could obtain it.
RFC 7519 describes the claims, UTF-8 representation, JOSE header, and JWS/JWE creation process; it does not require a particular programming language. Your application’s profile—not the JWT format alone—determines the claims and protection it needs.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minuteSet expiration and other validity rules
If an exp claim is present and processed, it identifies the time on or after which the token must not be accepted. Choose a lifetime appropriate to the application, and ensure the verifier actually checks it. Likewise, use nbf and iat only with clearly defined semantics and validation rules. The standard does not set one universal expiration period or require every token to include the same claims.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Verify the JWT before trusting it
A token that parses—or even has a valid signature—is not automatically intended for your service or authorized for a particular action. Verification should enforce the application’s cryptographic policy and then validate the claims relevant to the request.
- Constrain algorithms explicitly. Configure an allowlist of acceptable algorithms in the verifier; do not let the untrusted token header choose policy. RFC 8725, section 3.1, states: “Libraries MUST enable the caller to specify a supported set of algorithms and MUST NOT use any other algorithms when performing cryptographic operations.”
- Trust the right issuer and subject. Bind keys to trusted issuers, then check the issuer and subject—or issuer-subject pair—against what the application accepts.
- Check the audience when relevant. If the issuer creates tokens for more than one relying party or application, reject a missing or mismatched
aud. - Validate time and authorization claims. Check applicable time claims such as
expandnbf, along with each application-specific claim required for the operation. - Handle token-controlled key references cautiously. Do not blindly follow URLs in
jkuorx5u; RFC 8725 warns of server-side request forgery risks. Treatkidas untrusted input and avoid unsafe lookups or injection-prone handling.
These checks are specified in the JWT Best Current Practices. Use your library’s verification API, configure it to enforce the profile, and ensure the application rejects tokens that fail any required check.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Choose a library for your stack
Compare candidate libraries on the capabilities your application actually needs:
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →- Support for your language, runtime, and required JWS or JWE algorithms.
- A verifier configuration that lets you pin acceptable algorithms.
- Validation support for the required issuer, subject, audience, time, and application-specific claims.
- Integration with your key storage and rotation approach.
- Current maintenance and clear documentation for the version you deploy.
PyJWT and JJWT are examples for Python and Java respectively, not universal recommendations. Select a maintained implementation that fits your security requirements, and follow its official documentation for the version in use.
Quick Recap
Best Value
- POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

