- an open standard defining a compact and self-contained way for securely transmitting information between parties as a JSON object.
- stateless sessions (load balancers, separated front and back-end)
- easy logout
- save on SQL queries to check user or permissions every request