Skip to main content

Command Palette

Search for a command to run...

Understanding JWT Authentication in Node.js

Updated
•4 min read•View as Markdown

Modern applications need a way to identify users securely.

Whenever users:

  • log in

  • access private data

  • use protected routes

the server needs to verify their identity.

This process is called:

Authentication

One of the most commonly used authentication methods today is JWT authentication.


What is Authentication?

Authentication means verifying who the user is.

Example:

  • user enters email and password

  • server checks credentials

  • access is granted if valid

Without authentication:

  • anyone could access private data

  • accounts would not be secure

That is why authentication is important in backend systems.


What is JWT?

JWT stands for:

JSON Web Token

A JWT is a token used for securely transferring user information between client and server.

After successful login:

  • server generates a token

  • client stores the token

  • future requests send the token

Instead of storing user sessions on the server, the token itself carries authentication information.

This is called:

Stateless Authentication

because the server does not store session data.


Structure of a JWT

A JWT has three parts:

header.payload.signature

Example:

eyJhbGciOi...

The three sections are separated using dots.


The header contains information about:

  • token type

  • algorithm used

Example:

{
  "alg": "HS256",
  "typ": "JWT"
}

Payload

The payload contains user-related data.

Example:

{
  "id": 101,
  "name": "Ishan"
}

This data is called:

claims

Payload usually stores:

  • user ID

  • roles

  • permissions


Signature

The signature is used to verify that the token has not been modified.

Server generates it using:

  • secret key

  • header

  • payload

If someone changes token data, signature verification fails.


Login Flow Using JWT

The basic flow looks like this:

  1. User logs in

  2. Server validates credentials

  3. JWT token is generated

  4. Client stores token

  5. Future requests send token

  6. Server validates token

This removes the need for server-side sessions.


Sending Token with Requests

JWT tokens are usually sent inside request headers.

Example:

Authorization: Bearer <token>

The server reads the token and verifies it before allowing access.


Protecting Routes Using Tokens

Some routes should only be accessible to authenticated users.

Example:

  • profile page

  • dashboard

  • payment routes

Middleware is commonly used to verify tokens.

Example:

function verifyToken(req, res, next) {

  const token = req.headers.authorization

  if (!token) {
    return res.send("Access Denied")
  }

  next()
}

Here:

  • token is checked

  • request proceeds only if valid


Stateless Authentication (Simple Understanding)

Traditional session authentication stores user state on the server.

JWT works differently.

Instead:

  • token itself carries identity information

  • server only verifies token

This makes JWT scalable for:

  • APIs

  • mobile apps

  • distributed systems


Real-World Usage of JWT

JWT is heavily used in:

  • REST APIs

  • mobile authentication

  • frontend-backend separated apps

  • microservices

Because:

  • no session storage required

  • scaling becomes easier


Token Validation Lifecycle


Important Beginner Clarification

JWT does NOT automatically make applications secure.

Security still depends on:

  • strong secret keys

  • secure storage

  • HTTPS usage

  • token expiration handling

JWT is simply a method for authentication.


How to Think About JWT

Simple mental model:

  • login → receive token

  • future requests → send token

  • server verifies identity using token

That is the core idea.


One Line Summary

JWT authentication uses tokens to verify user identity without storing session data on the server.


Conclusion

JWT authentication became popular because it provides a scalable and stateless way to handle user authentication.

By sending tokens with requests instead of storing sessions, applications can authenticate users efficiently across APIs and distributed systems.

Understanding JWT is important because it is widely used in modern backend development.