Introduction
This appendix describes the JWT (JSON Web Token) format used by the API Server to encapsulate session or transaction confirmation information. Your app sends a transaction confirmation token to your backends as proof that the user's consent to the transaction was authenticated.
The API Server supports signed JWTs (JWS) and encrypted JWTs (JWE). The default token that is generated is a JWT that is signed with the symmetric HS256 algorithm with one secret key and has a lifespan of 1 hour. For detailed information about the JWT specification, see RFC 7519.
A JWS consists of a header, payload, and signature, these are separated by period ('.') characters. These are each Base64url strings. The header specifies the algorithm and key ID used for signing, see Signed JWT Header. The claims that make up the payload are described in Claim Set.

Figure 8 JWS Structure.
“JOSE” stands for Javascript Object Signing and Encryption. This is the name of the IETF working group that standardizes the representation of integrity-protected data using JSON data structures.
A JWE consists of a header, encrypted content encryption key, initialization vector, cipher text, and an authentication tag. These are separated by periods ('.'). Each section is a Base64url string. The encoded content that is the payload is in the Ciphertext section. The header contains the algorithm, content encryption algorithm, key ID, and issuer. See Encrypted JWT Header.

Figure 9 JWE Structure
Below is a JWS generated by the Digipass S3 API Server JWT Session plugin. The header is colored yellow, the payload is colored green, and the signature is blue.
eyJraWQiOiJoczI1Nl9rZXkiLCJhbGciOiJIUzI1NiJ9.eyJzdWIiOiJ6enoiLCJhdWQiOiJkZWZhdWx0IiwibmJmIjoxNTA2NjYzNzI3LCJpc3MiOiJodHRwczovL2V4YW1wbGUuY29tIiwiZXhwIjoxNTA2NjY3MzI3LCJpYXQiOjE1MDY2NjM3Mjd9.H7241dL6wrpQuz2ExNnUH2JhRw9eiIrh7Yb83x2RPnY
The above JWS is signed with HMAC using the SHA-256 hash algorithm with the following secret key (JWK):
{
"kty":"oct",
"use":"sig",
"kid":"hs256_key",
"k":"-MooF_CY4pElMmcNZu93BJQUeQg_E9HwBu1LONc_WXA"
}You can use the online JWT debugger tool at jwt.io to decode the token and verify the signature.