SkillByAIOpen interactive version →

Authentication & Authorization

Build identity systems that hold up: password storage, sessions and cookies, JWTs, OAuth 2.0 and OpenID Connect, MFA and passkeys, and authorization models enforced in real APIs.

Start course →

What you'll learn

Syllabus

Identity Foundations

  1. Authentication Versus Authorization
  2. Principals, Credentials and Factors
  3. Threat Model for Login

Passwords Done Right

  1. Storing Passwords
  2. Designing the Login Flow
  3. Password Reset and Email Verification

Sessions and Cookies

  1. Server-Side Sessions
  2. Secure Cookie Attributes and CSRF
  3. Session Lifecycle

Tokens and JWT

  1. JWT Structure and Signing
  2. Verifying JWTs Correctly
  3. Access Tokens, Refresh Tokens and Browser Storage

OAuth 2.0 and OpenID Connect

  1. Roles and the Authorization Code Flow With PKCE
  2. OpenID Connect: ID Tokens, Userinfo and Access Tokens
  3. Client Credentials and Discouraged Grants

Strong and Modern Authentication

  1. MFA Options
  2. Passkeys and WebAuthn
  3. Social Login and Account Linking

Authorization Models

  1. RBAC, ABAC and ReBAC
  2. Enforcing Authorization in APIs
  3. Multi-Tenant Isolation

Production Identity

  1. Using Identity Providers
  2. Auditing and Monitoring Auth Events
  3. API Keys and Service Accounts
  4. An Identity Checklist