Auth & JWT

Passwords travel the internet. Let’s disguise them.

▶ the lesson · ~35s · narrated · tap for sound

the intro

Authentication proves who you are; authorization decides what you may do. The common flow: user logs in, server issues a signed token (like a JWT), and the client sends it with every request. Sessions keep state on the server; JWTs carry proof with them.

the sample

the token handshake

POST /login  { email, password }
→ { token: "eyJhbGci..." }

GET /me
Authorization: Bearer eyJhbGci...

fun fact ✦

bcrypt is deliberately slow — a 100ms password check ruins brute-force attacks.

the docs

quick hits about Auth & JWT

15-second answers · interviews, tips, trivia & hidden gems

🎤 interview

Authentication vs authorization?

🎤 interview

Sessions or JWT?

🎤 interview

How does “sign in with Google” work?

📚 tutorial

How do you store passwords?

🔧 useful

Who guards your routes?

💎 deep

Where should the token live?

💎 deep

Why do access tokens expire so fast?

🧠 trivia

Why is bcrypt… slow?