What you'll learn
A JWT is a signed message, not an automatic session strategy. Use short-lived access tokens only when distributed verification helps, validate every relevant claim, and keep refresh-token state revocable.
By the end of this lesson, you'll be able to:
- Select sessions or tokens by architecture
- Validate algorithm, issuer, audience, and expiry
- Rotate refresh tokens
- Detect replay and revoke token families
Core mental model
Node.js becomes easier when you separate the JavaScript language from the runtime and the operating-system capabilities it exposes. Use this table as a decision guide.
| Concept | What it means | Decision rule |
|---|---|---|
| Access token | Short-lived authorization evidence | Keep scope narrow and lifetime brief |
| Refresh token | Longer-lived credential used to obtain access | Store a server-side hash and rotate every use |
| Token family | A refresh lineage for one login | Revoke the family when an already-rotated token reappears |
Professional workflow
Build and verify Node.js programs from the terminal in small, observable steps.
- Define the token lifecycle boundary: inputs, outputs, invariants, ownership, and expected failures.
- Design the data or message contract before choosing implementation details.
- Implement the smallest correct path with dependencies passed explicitly.
- Add validation, failure translation, cleanup, and concurrency behavior.
- Verify the boundary with realistic data and at least one adversarial case.
- Measure or observe the behavior before optimizing or extracting abstractions.
Keep the feedback loop short
Guided code lab
Verify an explicit token contract
A maintained JOSE library handles cryptography while the application pins the expected issuer, audience, and algorithm.
const { payload } = await jwtVerify(token, publicKey, {
algorithms: ['RS256'],
issuer: 'https://auth.example.test',
audience: 'task-api',
clockTolerance: 5,
});
if (payload.typ !== 'access' || typeof payload.sub !== 'string') {
throw new UnauthorizedError();
}Production practice
Contract
Verification pins cryptographic and semantic claims; refresh exchange is single-use, atomic, hashed at rest, and revocable.
Verification
Test wrong algorithm, key, issuer, audience, type, expiry, future not-before, changed scope, refresh reuse, and family revocation.
Operations
Rotate signing keys with key IDs, keep clocks synchronized, monitor reuse detections, and publish a compromise procedure.
Common failure mode
Independent workshop
Implement an access/refresh flow with replay detection.
Your finished workshop must include:
- Documented token claims
- Pinned verification
- Short access lifetime
- Hashed refresh records
- Atomic rotation
- Family revocation test
Definition of done
Recap & quick check
Key takeaways
- JWTs are signed messages
- Every claim is a contract
- Access tokens stay short-lived
- Refresh tokens remain stateful
- Replay revokes the family
Quick check
1. Is decoding a JWT authentication?
2. What should happen on refresh reuse?
3. Why pin audience?
Next: Authorization, RBAC & Multi-Tenancy