A JWT Is Made of a Header, a Payload, and a Signature
A JWT is three base64url-encoded parts joined by dots, in the form header.payload.signature. The header names the signing algorithm. The payload holds data called claims, such as the user's id and an exp field for the expiry time.
The signer computes the signature from the header and payload with a signing key. The verifier recomputes it and checks that the two match, which confirms the header and payload haven't changed since signing. Changing even one character of the payload produces a completely different signature, so a mismatch reveals tampering.
The payload is only encoded, not encrypted, so anyone can read it without a key. Verification confirms that nothing was tampered with, not that the contents are secret.
Break a JWT into its three parts, and explain what signature verification and expiry checking each confirm.
A JWT's payload is changed from { "role": "user" } to { "role": "admin" }, without re-signing it. What happens when the server verifies it?