Authentication & Authorization

Build identity systems that hold up: password storage, sessions and cookies, JWTs, OAuth 2.0 and OpenID Connect, MFA and passkeys, and authorization models enforced in real APIs.

Start course →

What you'll learn

  • Distinguish authentication from authorization and model the threats against a login system.
  • Store passwords with Argon2id or bcrypt and design safe login, reset and verification flows.
  • Run secure cookie-based sessions with correct attributes, CSRF defences and lifecycle rules.
  • Issue and verify JWTs correctly and choose safe token storage in browsers.
  • Implement OAuth 2.0 and OpenID Connect flows (authorization code with PKCE, client credentials) and add MFA and passkeys.
  • Enforce RBAC, ABAC and relationship-based authorization in APIs and operate identity safely in production.

Syllabus

Identity Foundations

  1. Authentication Versus Authorization
  2. Principals, Credentials and Factors
  3. Threat Model for Login

Passwords Done Right

  1. Storing Passwords
  2. Designing the Login Flow
  3. Password Reset and Email Verification

Sessions and Cookies

  1. Server-Side Sessions
  2. Secure Cookie Attributes and CSRF
  3. Session Lifecycle

Tokens and JWT

  1. JWT Structure and Signing
  2. Verifying JWTs Correctly
  3. Access Tokens, Refresh Tokens and Browser Storage

OAuth 2.0 and OpenID Connect

  1. Roles and the Authorization Code Flow With PKCE
  2. OpenID Connect: ID Tokens, Userinfo and Access Tokens
  3. Client Credentials and Discouraged Grants

Strong and Modern Authentication

  1. MFA Options
  2. Passkeys and WebAuthn
  3. Social Login and Account Linking

Authorization Models

  1. RBAC, ABAC and ReBAC
  2. Enforcing Authorization in APIs
  3. Multi-Tenant Isolation

Production Identity

  1. Using Identity Providers
  2. Auditing and Monitoring Auth Events
  3. API Keys and Service Accounts
  4. An Identity Checklist