A JWT looks like xxxxx.yyyyy.zzzzz. The first part says which signing algorithm is used, the second is a JSON object with claims like the user ID and expiry, and the third is a cryptographic signature that lets the server confirm the token wasn't tampered with.
Because the payload is only Base64-encoded, anyone can read it — you should never put passwords or secrets inside a JWT. The safety comes from the signature, which requires a private key or shared secret to forge.
JWTs are the default session format for most modern APIs, single-page apps, and OAuth 2.0 / OpenID Connect flows.