Module 06 of 10

Authentication & Security

Lessons

About This Module

Once your API is live, the next question is who is allowed to use it. Authentication proves who a user is, and authorization decides what they can do. Getting either wrong puts your users' data at risk, so this module covers the core building blocks every backend developer needs to know.

You'll compare the main ways of authenticating on the web, including sessions, cookies, and tokens, then look closely at JWTs and at OAuth 2.0, the standard behind "Log in with Google". From there the focus moves to protecting the data itself: how to store passwords safely with hashing and salting, and how HTTPS keeps traffic private between the browser and your server.

With a secure API in place, you'll be ready to make it faster and more reliable in Caching & Web Servers, the next module in this course.

Lessons

5 videos
01

Web Authentication Methods Explained

How authentication works on the web and the main types available to developers, giving you a map of the options before you dig into each one.

02

What Is JWT and Why Should You Use It

What a JSON Web Token is, how its parts work, why it is secure, and when to choose it over traditional session-based authorization.

03

OAuth 2 Explained in Simple Terms

How OAuth 2.0 lets one app get limited access to your data on another service without ever seeing your password.

04

How to Store Passwords Safely in a Database

Why plain-text passwords and bare hashes are not enough, and how salting protects stored passwords against precomputed attacks.

05

How Does HTTPS Work?

How HTTPS encrypts the traffic between a browser and a server, and what happens during the handshake before any data is sent.