What is a JWT, in plain language?
PICTURE THIS: A SENTENCE BECOMES TOKENS
The model does not read letters like humans. It reads these pieces, then predicts the next one.
Simple meaning
A JSON Web Token is a signed string with a header, payload, and signature, often used as a bearer access token.
WHY — Auth instead of guessing?
Why interviewers care about Auth:
who only read docs from people who shipped.
and tied to Backend work.
Name the idea, why it exists, then one short example.
End with when you use it and one common pitfall.
STEPS — What happens with tokens?
Before the model can read a sentence, it goes through these steps:
- 1A JSON Web Token
is a signed string with a header, payload, and signature, often used as a bearer access token.
- 2The server can verify
the signature without a session lookup, which helps stateless scale-out.
- 3Anyone who holds the
token is treated as that user until it expires, so you must protect it in transit and at rest.
- 4Context mix
Attention looks at nearby tokens together.
- 5Next token
The model scores what should come next.
- 6Decode
IDs turn back into readable text.
EXAMPLE — See it in action
Let's see how a real sentence is tokenized (tokens may vary by model):
Note: Actual tokens and IDs depend on the tokenizer (e.g., GPT, Llama, etc.).
Key takeaway
A JSON Web Token is a signed string with a header, payload, and signature, often used as a bearer access token. The server can verify the signature without a session lookup, which helps stateless scale-out.