Lesson 17 / 25
JWT-Based Auth
Learn how JWTs carry signed claims for stateless authentication, and why short-lived tokens plus refresh tokens matter.
Three signed parts
A JWT (JSON Web Token) is header.payload.signature, base64-encoded. The payload holds claims (user id, roles, expiry); the signature — made with a server secret or private key — proves it wasn't tampered with.
Stateless verification
A server can verify a JWT's signature without a database lookup or a shared session store — any node with the public key/secret can validate it. That's why it fits stateless REST APIs so well.
Short expiry, refresh tokens
A JWT can't be easily revoked mid-flight — it's valid until it expires. Keep access tokens short-lived (minutes) and pair them with a separate, revocable refresh token to get new ones.