Auth & JWT
Passwords travel the internet. Let’s disguise them.
▶ the lesson · ~35s · narrated · tap for sound
the intro
Authentication proves who you are; authorization decides what you may do. The common flow: user logs in, server issues a signed token (like a JWT), and the client sends it with every request. Sessions keep state on the server; JWTs carry proof with them.
the sample
the token handshake
POST /login { email, password }
→ { token: "eyJhbGci..." }
GET /me
Authorization: Bearer eyJhbGci...fun fact ✦
bcrypt is deliberately slow — a 100ms password check ruins brute-force attacks.
the docs
quick hits about Auth & JWT
15-second answers · interviews, tips, trivia & hidden gems
🎤 interview
Authentication vs authorization?
🎤 interview
Sessions or JWT?
🎤 interview
How does “sign in with Google” work?
📚 tutorial
How do you store passwords?
🔧 useful
Who guards your routes?
💎 deep
Where should the token live?
💎 deep
Why do access tokens expire so fast?
🧠 trivia
Why is bcrypt… slow?