Compact, digitally signed token format. The Microsoft identity platform issues its access and ID tokens this way, and clients send them to REST APIs.
Also called JSON Web Token.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains JWT in context, with comparison tables and the common traps.
Terms in this definition
- Token
The unit of text an LLM works with, which may be a word, part of a word or punctuation. Billing, limits and context windows are all counted in these units.
- FORMAT
A DAX function that turns a value into text according to a format string, for instance "MMMM" to show a month's name. Since the output is text, numeric operations can't use it, and dynamic format strings were introduced to get around that.
- IDENTITY
A column property, written IDENTITY(seed, increment), that gives each new row the next number in a rising sequence. SCOPE_IDENTITY reports the latest value created in the current scope, and a rolled-back transaction still uses up the numbers it took.
- REST
Short for representational state transfer, the style of HTTP API that Azure services expose.
Related terms
- API Management validate-jwt policy
API Management inbound policy validating a JWT's issuer, audience, signature and required claims, for instance using the Microsoft Entra OpenID configuration. By default it answers 401 when a token is absent or invalid.
- validate-azure-ad-token
An inbound API Management policy built specifically for Microsoft Entra tokens, checking the JWT's tenant, client application IDs, audiences and claims; a specialised option instead of validate-jwt.
- validate-jwt
Before API Management passes a request on to the back end, this policy confirms the JWT has the expected issuer, audience and claims.