Authentication & Authorization
Build identity systems that hold up: password storage, sessions and cookies, JWTs, OAuth 2.0 and OpenID Connect, MFA and passkeys, and authorization models enforced in real APIs.
What you'll learn
- Distinguish authentication from authorization and model the threats against a login system.
- Store passwords with Argon2id or bcrypt and design safe login, reset and verification flows.
- Run secure cookie-based sessions with correct attributes, CSRF defences and lifecycle rules.
- Issue and verify JWTs correctly and choose safe token storage in browsers.
- Implement OAuth 2.0 and OpenID Connect flows (authorization code with PKCE, client credentials) and add MFA and passkeys.
- Enforce RBAC, ABAC and relationship-based authorization in APIs and operate identity safely in production.
Syllabus
Identity Foundations
Passwords Done Right
Sessions and Cookies
Tokens and JWT
OAuth 2.0 and OpenID Connect
- Roles and the Authorization Code Flow With PKCE
- OpenID Connect: ID Tokens, Userinfo and Access Tokens
- Client Credentials and Discouraged Grants