Session Authentication and JWT
HTTP is stateless. Maintaining user authentication requires storing state somewhere. This post covers the structure, trade-offs, and storage strategies of server-side sessions and client-side JWT tokens.
HTTP is stateless. Maintaining user authentication requires storing state somewhere. This post covers the structure, trade-offs, and storage strategies of server-side sessions and client-side JWT tokens.
There was a time I called JWT an authentication method and said I logged in with OAuth, and the terms kept blurring together. This post lines up Basic, Digest, API Key, Session, Token, OAuth, OIDC, and SSO by two questions: authentication vs authorization, and where the proof of identity lives.
A startup born from a casual League of Legends habit. From architecture design to desktop apps, a record of two people building a service that grew to 10,000 users over five months.