JWT Security

Difficulty: Intermediate

Question

What is a JWT? How do you store it safely on the client?

Answer

JWT consists of Header, Payload, and Signature. Store in **HTTP-only, Secure, SameSite=Strict cookies** to protect against XSS and CSRF. LocalStorage is vulnerable to XSS.

Concepts covered

JWT, Header, Payload, Signature, XSS, CSRF