Once your API is live, the next question is who is allowed to use it. Authentication proves who a user is, and authorization decides what they can do. Getting either wrong puts your users' data at risk, so this module covers the core building blocks every backend developer needs to know.
You'll compare the main ways of authenticating on the web, including sessions, cookies, and tokens, then look closely at JWTs and at OAuth 2.0, the standard behind "Log in with Google". From there the focus moves to protecting the data itself: how to store passwords safely with hashing and salting, and how HTTPS keeps traffic private between the browser and your server.
With a secure API in place, you'll be ready to make it faster and more reliable in Caching & Web Servers, the next module in this course.
How authentication works on the web and the main types available to developers, giving you a map of the options before you dig into each one.
What a JSON Web Token is, how its parts work, why it is secure, and when to choose it over traditional session-based authorization.
How OAuth 2.0 lets one app get limited access to your data on another service without ever seeing your password.
Why plain-text passwords and bare hashes are not enough, and how salting protects stored passwords against precomputed attacks.
How HTTPS encrypts the traffic between a browser and a server, and what happens during the handshake before any data is sent.