The token contains encoded header and claim sections plus a signature or message-authentication code. A verifier checks the algorithm, signature, issuer, audience, and time-based claims before trusting it. Encoding is not encryption, so readable token contents should not contain unprotected secrets.