The first part of the JWT is the token header which varies according to whether the JWT is signed or encrypted. The following sections show example JWT headers and parameters descriptions for signed and encrypted JWTs.
Signed JWT header
{
"alg":"HS256",
"kid":"hs256_key"
}Parameter | Description |
|---|---|
alg | Mandatory. The digital signature or MAC algorithm to use with JWS. |
kid | The key used to sign the message. |
typ | Optional. The media type. See “typ" in RFC 7519. |
Encrypted JWT header
{
"alg":"RSA-OAEP",
"enc":"A256GCM",
"kid":"rsa-enc-2048",
"iss":"https:\/\/example.com:8443"
}Parameter | Description |
|---|---|
alg | The encryption algorithm to encrypt the Content Encryption Key (CEK). |
enc | The content encryption algorithm. |
kid | The key used to encrypt the CEK. |
iss | The token issuer. Used at validation to get an appropriate CEK decryption key. |
typ | Optional. The media type. See “typ" RFC 7519. |