The data inside JWT is signed and encrypted, it does not mean that it is secure. JWT does not provide guarantee for sensitive data. data is encrypted using a private key which is known to both the parties i.e. sender and receiver, an intruder can brake the key and may change the content.

