Claims and encoding
The header identifies the selected signing algorithm, while the payload contains claims such as sub, iss, aud, iat, nbf, and exp. Header and payload JSON are separately encoded with base64url and joined by a period. Base64url is an encoding, not confidentiality protection, so names, identifiers, and other payload values remain inspectable.