You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

为何JWT令牌的Header和Payload总是以eyJ开头?

Great question! Let's break this down clearly so you understand exactly what's going on.

Why JWT Headers & Payloads Start with eyJ

First, a quick recap: JWTs are split into three dot-separated parts: Header, Payload, and Signature. The first two parts aren't stored as plain JSON—they're encoded using Base64URL (a URL-safe variant of standard Base64).

Here's the key reason for the eyJ prefix:

  • Standard JWT Headers are always JSON objects that start with {" (e.g., {"alg": "HS256", "typ": "JWT"}).
  • Standard JWT Payloads are also JSON objects, so they almost always start with {" too (e.g., {"sub": "1234567890", "name": "John Doe"}).

When you Base64URL-encode the string {", you get eyJ—that's the exact prefix you're seeing.

It's worth noting that this isn't a mandatory rule in the JWT spec, but in practice, every valid, standard-compliant JWT will have this prefix. The only way you wouldn't see eyJ is if someone created a non-standard JWT with a non-JSON Header/Payload—which is extremely rare and defeats the purpose of using JWT in the first place.

To wrap it up:

  • eyJ is the Base64URL-encoded version of {"
  • Since JWT Header/Payload are JSON objects starting with {", their encoded forms start with eyJ

内容的提问来源于stack exchange,提问作者Suresh Prajapati

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.21 04:26:20