What Is JWT and How Does It Work in 2026?
Learn what JWT is, how it works, its token structure, advantages, security challenges, as well as its adoption and future in Indonesia in 2026.

According to global data from various cybersecurity research institutions, more than 85% of modern web and mobile applications now rely on token-based authentication, and JSON Web Token (JWT) remains the de facto standard for stateless authorization in 2026. The massive growth of API-first adoption and microservices architecture—coupled with the rise of credential-based cyberattacks—makes a deep understanding of JWT no longer an option but a necessity for developers, system architects, and digital product owners. Amid the major transition toward zero-trust architecture and increasingly distributed edge computing, JWT serves as a critical foundation that enables systems to trust each other without needing to know each other directly. JWT is an open standard in the form of a structured token that enables the exchange of security claims between parties in a compact, secure, and self-contained manner, without the need to store session state on the server.
What Is JWT? A Digital Token That Carries Its Own Identity
Imagine JWT as a cryptographically signed digital identity card. When you enter a modern office building, the security guard does not need to call headquarters to verify your identity every time you pass through—they simply check the card you carry, ensure the stamp and signature are genuine, and then allow you in. JWT works on the same principle: this token carries information about who you are, what access rights you have, and when the card expires, all packaged in a single object that can be verified for authenticity without needing to query a central database.
Technically, JWT is a long string consisting of three parts separated by dots. Each part has a specific role:
Header contains metadata about the token type and the signature algorithm used, for example HS256 (HMAC with SHA-256) or RS256 (RSA with SHA-256), so that the recipient knows how to verify its authenticity.
Payload contains claims—statements about an entity and additional data—such as user identity, roles, access rights, expiration time, and other metadata needed by the application to make authorization decisions.
Signature is the result of a cryptographic computation of the header and payload using a secret key or private key, which serves to ensure that the token has not been modified since it was issued and truly originates from a legitimate issuer.
JWT has several common subtypes or usage profiles:
JWS (JSON Web Signature) is the most common form, where the token content is cryptographically signed to guarantee integrity and authenticity, although its contents remain readable by anyone holding the token.
JWE (JSON Web Encryption) encrypts the entire token content so that only parties holding the decryption key can read the claims inside, suitable for sensitive data that must not leak even if the token is intercepted.
Nested JWT combines JWS and JWE, where the token is signed first and then encrypted, providing a double layer of security for scenarios with high privacy requirements.
Distributed JWT refers to a pattern where tokens are issued by a central service and verified by many other services without needing to share a secret key, commonly using asymmetric key pairs.
Why JWT Matters: The Unignorable Foundation of Modern Authentication
1. Statelessness That Enables Horizontal Scalability
In traditional monolithic architecture, user sessions are stored in server memory, which means every request must return to the same server for validation. This becomes a major obstacle when applications need to scale horizontally with many server instances behind a load balancer. JWT fundamentally changes this paradigm: the server does not need to store any session state because all the required information is already inside the token itself. When a request arrives, the server simply verifies the token signature, checks claims such as expiration time and access rights, and then processes it immediately. As a result, dozens or even hundreds of server instances can handle requests from the same user without needing session synchronization between servers, making JWT a key pillar for high-traffic systems with dynamic scalability needs.
Case Study – Large-Scale E-commerce Platform: An e-commerce platform serving millions of daily active users reported that migrating from database-based sessions to JWT managed to cut average authentication latency by up to 40% and significantly reduce session database load, allowing them to handle seasonal traffic spikes without expensive infrastructure additions.
2. Cross-Platform and Cross-Language Interoperability
JWT is designed as an open standard that is not tied to any programming language, framework, or platform. A token issued by a service written in Go can be verified by another service written in Python, Java, Node.js, Rust, or any language that has a JWT library. This characteristic is crucial in the era of polyglot and microservices architecture, where each team can choose the technology that best suits its needs without worrying about authentication compatibility. Moreover, JWT runs seamlessly across various channels: web applications, native mobile, IoT devices, and machine-to-machine communication, making it a universal choice for exchanging security claims in an increasingly heterogeneous digital ecosystem.
Case Study – Multi-Product Fintech Company: A fintech company operating dozens of microservices with teams spread across multiple time zones adopted JWT as a single standard for both internal and external authentication, cutting new service integration time from weeks to days thanks to the elimination of session synchronization needs and differing authentication formats.
3. Supporting Distributed Authentication and Zero-Trust
Zero-trust architecture has become the dominant security framework in 2026, and JWT is one of the most important tools to realize it. In the zero-trust model, every request must be verified independently without assumptions of trust based on network location or previous sessions. JWT enables this by being a carrier of claims that can be verified at every hop of the request journey. Each service receiving a request can validate the token independently using the issuer's public key, without needing to contact a central authentication service for every request. This reduces latency, eliminates single points of failure, and enables more granular security policies based on claims embedded in the token, such as access scope, time, location, or identity assurance level.
Case Study – Logistics Company with IoT Fleet: A large logistics company operating thousands of IoT devices for fleet tracking and smart warehouse management uses JWT to secure device-to-cloud and cloud-to-cloud communication, enabling distributed verification at the edge without burdening the network with repeated verification requests.
4. Efficiency and Infrastructure Load Reduction
With traditional sessions, every request requiring authentication typically triggers one or more database queries to retrieve session data. At scale, this can mean millions of additional database queries every day that consume computing resources and slow down responses. JWT eliminates this need because the token is self-contained: all data needed for authorization is already inside the token and can be read after signature verification. Furthermore, since no session data is stored, the cost of storing and replicating session data also disappears. On the client side, tokens can be stored in memory or secure storage and attached to every request, making the authentication process very lightweight and fast. This efficiency becomes increasingly important in 2026 when applications are required to respond in milliseconds and cloud computing costs are more strictly accounted for.
JWT Adoption in Indonesia: From Startups to Government Institutions
Indonesia in 2026 shows increasingly mature and widespread JWT adoption, in line with the acceleration of digital transformation in both the private and public sectors. More and more companies realize that monolithic architecture with server-based sessions can no longer support explosive digital user growth, while national and regional security standards increasingly demand strong and auditable authentication practices. JWT emerges as a balanced answer between security, scalability, and cost efficiency.
Key Players: In Indonesia, JWT adoption is largely driven by global authentication service providers such as Auth0 (part of Okta), Amazon Cognito, Firebase Authentication, and Supabase Auth that offer ready-to-use JWT implementations. However, many large companies and government agencies also develop internal JWT-based authentication services using popular open source libraries such as jsonwebtoken for Node.js, PyJWT for Python, jose for JavaScript, and jjwt for Java. Among local developer communities, discussions and workshops on secure JWT implementation are increasingly held by communities such as JakartaJS, SurabayaDev, and various Google Developer Group chapters in Indonesia.
Local Success Stories:
A multinational ride-hailing company based in Jakarta uses JWT to secure millions of user sessions and communication among hundreds of microservices, enabling a seamless user experience in driver and passenger applications with authentication latency below 100 milliseconds.
A leading digital bank in Indonesia utilizes JWT with a JWE combination to protect sensitive data in banking transactions and partner API authentication, ensuring compliance with OJK regulations and PCI-DSS standards while maintaining a fast user experience.
An edtech platform serving tens of millions of students adopts JWT to manage access to learning content, online exams, and integration with school systems, enabling cross-platform authentication from the diverse devices used by students across the archipelago.
A national telemedicine service uses JWT to secure the exchange of electronic medical record data between patient applications, hospital systems, and pharmacy services, with a focus on data privacy and compliance with the Personal Data Protection Law.
Government institutions in digital public services utilize JWT as part of the national digital identity infrastructure, enabling interoperability among e-government services without needing to build separate authentication systems for each application.
Challenges & How to Overcome Them
1. Tokens That Cannot Be Revoked Instantly
Because JWT is stateless, the server has no record of which tokens are still valid after they are issued. If a token is stolen or a user logs out, the token that has already been circulated will still be considered valid until its expiration time runs out. This is the biggest trade-off of stateless architecture and becomes a serious security gap if not handled properly. The solution is to implement a token denylist in fast storage such as Redis or Memcached, where revoked tokens are stored until they expire. However, this solution brings back some state to the server, so it needs to be considered wisely. A more modern alternative is to use long-lived refresh tokens stored on the server to issue very short-lived access tokens, for example 5-15 minutes, so that the risk of a stolen token is minimized. Another approach is to utilize a distributed token revocation list based on event streaming so that all services can update the denylist in real-time without becoming a bottleneck.
2. Risk of Token Leakage on the Client Side
Token storage on the client side is a vulnerable point that is often overlooked. Storing JWT in localStorage makes it vulnerable to cross-site scripting (XSS) attacks, while storing it in cookies without proper security attributes makes it vulnerable to cross-site request forgery (CSRF). Both are attack vectors that are still very active in 2026. The solution is to implement strict storage practices: use cookies with HttpOnly, Secure, and SameSite attributes for web applications so that tokens cannot be accessed by JavaScript and are not sent cross-site, or use platform secure storage such as Keychain on iOS and Keystore on Android for mobile applications. In addition, implement a strict Content Security Policy (CSP) to prevent malicious script execution, and always perform input sanitization to avoid XSS vulnerabilities. For single-page applications that cannot avoid localStorage, consider storing tokens in memory and using refresh tokens with rotation to limit the impact of leakage.
3. Incorrect Algorithm Configuration
One of the most classic vulnerabilities still frequently found in 2026 is incorrect configuration of the signature verification algorithm. Some old implementations allow the server to accept tokens with a header stating the "none" algorithm, meaning the token is not signed at all, so attackers can easily create fake tokens. Another vulnerability is algorithm confusion between HMAC and RSA, where an attacker can use the public key as an HMAC secret key. The solution is to lock the allowed algorithms on the server side explicitly—never read the algorithm from the token header without whitelist validation—and strictly separate keys for HMAC and RSA/ECDSA. Always use well-maintained JWT libraries that have passed security audits, and implement automated testing that covers cases of modified tokens, tokens with disallowed algorithms, and tokens with invalid signatures. Periodic audits of authentication implementation should also be part of the team's security routine.
4. Overexposure of Information in Payload
Because the JWT payload is only encoded with Base64Url and not encrypted, anyone holding the token can easily read its contents. This becomes a serious problem if developers include sensitive data such as email addresses, phone numbers, or even financial information directly in the payload. In an era of increasingly strict privacy regulations such as the Personal Data Protection Law in Indonesia and GDPR in Europe, this practice can lead to legal violations. The solution is to minimize claims in the payload—only include information truly needed for authorization, such as user ID, role, and expiration time. Additional sensitive data should be retrieved from the server after successful authentication. If the payload must carry sensitive data, use JWE to encrypt the entire token, or use opaque token references that point to data on the server. Always assume that the token payload can be read by anyone and design claims with the principle of least privilege.
The Future of JWT
Adoption of updated JWT standards with post-quantum algorithms will become increasingly urgent as the threat of quantum computing approaches, driving a gradual migration from RSA and ECDSA to quantum-resistant algorithms already standardized by NIST in the middle of this decade.
Integration with decentralized identity and verifiable credentials will make JWT a bridge between traditional authentication systems and blockchain-based decentralized identity ecosystems, enabling users to control their own identity data.
Increased use of JWT for machine-to-machine communication in edge computing and IoT will expand further, with very short-lived tokens and automatic rotation to reduce the risk of token theft on distributed devices.
Stricter standardization of token formats that are interoperable across vendors will be driven by the real need to avoid vendor lock-in and facilitate migration between authentication service providers, in line with the increasingly dominant open standards principles.
Conclusion: JWT as an Ever-Evolving Digital Security Pillar
JWT has proven itself as one of the foundational technologies in the modern digital security landscape, and its relevance in 2026 is actually strengthening along with the acceleration of distributed architecture, zero-trust, and increasingly widespread connectivity. Understanding how JWT works is not merely a technical skill for developers, but a strategic competency for anyone involved in building and managing secure and scalable digital products. With correct implementation—from selecting the right algorithm, disciplined key management, to careful token lifecycle handling—JWT becomes a solid foundation for an authentication system that is efficient, secure, and ready to face future security challenges.