What is JWT?
JSON Web Token — a base64-encoded JSON payload signed (HMAC or RSA/ECDSA) so the server can verify the token's authenticity without a database lookup. Used to authenticate API requests statelessly. Anyone can READ a JWT's contents (base64 isn't encryption); only signing key holders can produce valid ones.