Encoded

JSON Web Token

Decoded

Header:

Payload:

Signature is Validation (Key is NEEDED)

signHMACSHA256(
  base64Url(header) + "." +
  base64Url(payload),
)