Auth and API Security
Sign-in done right: password hashing, sessions, JWTs, OAuth with PKCE, authorization, rate limits and two-factor codes, built and tested in every lesson.
27 lessons across 8 units: secure tokens and NIST password rules, PBKDF2 and scrypt, cookies, sessions and CSRF, JWTs from scratch, refresh token rotation, OAuth 2.0 with PKCE and OpenID Connect, roles and object-level authorization, rate limiting, TOTP, and a secure auth API boss, with 37 runnable examples, quizzes and 27 coding problems.
- Units
- 8
- Lessons
- 27
- Coding problems
- 27
- Examples
- 37
Free: units 1 to 2 (7 lessons). Units 3 to 8 with DevArcade Pro.
What you'll learn
- Identity and SecretsAuthentication versus authorization, random tokens and constant-time checks, and password rules from NIST SP 800-63B.
- Storing PasswordsPBKDF2, scrypt and Argon2id with OWASP parameters, logins that leak nothing, and password reset tokens.
- Cookies and SessionsCookie flags, HMAC-signed cookies, server-side sessions with timeouts, and CSRF defenses.
- JSON Web TokensJWTs from scratch: signing, a complete verifier, the classic pitfalls, and Bearer middleware with scopes.
- Refresh Tokens and OAuthRefresh token rotation with reuse detection, the authorization code flow with PKCE, and OpenID Connect sign-in.
- AuthorizationRoles and permissions, object-level checks against BOLA, and scoped API keys.
- Abuse and Second FactorsRate limiting, login throttling and lockout, HOTP and TOTP from the RFCs, and two-factor enrollment.
- Shipping Secure AuthSecure defaults and audit logs, then the boss: a complete auth API on Express and MongoDB.
Course outline
8 units and 27 lessons. Each lesson has a short read with examples you run, a quiz, and coding problems tested in your browser; most have a step-through visualizer.
- Free
Unit 1:Identity and Secrets
Authentication versus authorization, random tokens and constant-time checks, and password rules from NIST SP 800-63B.
- Authentication and Authorization Who are you (authentication) versus what may you do (authorization), how credentials travel in HTTP, and when to answer 401 or 403.1 problem
- Random Tokens and Constant-Time Checks Generate unguessable tokens with crypto.randomBytes, encode them as base64url, store only their hash, and compare secrets with timingSafeEqual.1 problem
- Password Rules That Help What NIST SP 800-63B asks of password checks today: length over complexity, no forced rotation, blocklists, Unicode, and letting password managers work.1 problem
-
- Free
Unit 2:Storing Passwords
PBKDF2, scrypt and Argon2id with OWASP parameters, logins that leak nothing, and password reset tokens.
- Hashing Passwords Why plain text, encryption and fast hashes all fail when a database leaks, what salts do, and PBKDF2 with the iteration counts OWASP recommends.1 problem
- Memory-Hard Hashes: scrypt and Argon2id Why memory-hard functions resist GPU cracking better than PBKDF2, OWASP's parameters for Argon2id and scrypt, and using crypto.scrypt in Node.1 problem
- Verifying Logins Safely A login check that does not reveal which emails have accounts (by message or by timing), upgrades old hashes when users sign in, and treats the email as an identifier, not a secret.1 problem
- Password Reset Tokens A reset flow that survives scrutiny: random single-use tokens stored as hashes, short expiry, one live token per account, and responses that do not reveal which emails exist.1 problem
-
- Pro
Unit 3:Cookies and Sessions
Cookie flags, HMAC-signed cookies, server-side sessions with timeouts, and CSRF defenses.
- Cookies and Their Flags How Set-Cookie and Cookie work, and the attributes that protect a session cookie: HttpOnly, Secure, SameSite, Path, Max-Age and the __Host- prefix.1 problem
- Signing Cookies with HMAC Detect tampering by appending an HMAC of the value, verify it in constant time, rotate secrets without logging everyone out, and remember that signed is not secret.1 problem
- Server-Side Sessions Keep session data on the server behind a random id: store only its hash, rotate the id at login, and expire sessions on idle and absolute timeouts.1 problem
- Cross-Site Request Forgery Why browsers attach cookies to requests other sites trigger, and the layered defenses: SameSite cookies, Origin and Fetch Metadata checks, and tokens tied to the session.1 problem
-
- Pro
Unit 4:JSON Web Tokens
JWTs from scratch: signing, a complete verifier, the classic pitfalls, and Bearer middleware with scopes.
- Anatomy of a JWT A JSON Web Token is base64url(header).base64url(payload).signature: the registered claims, signing with HS256 from scratch, and why anyone can read the payload.1 problem
- Verifying JWTs What a verifier must check, in order: structure, an allowlisted algorithm, the signature in constant time, then exp, nbf, iss and aud, with a small clock tolerance.1 problem
- JWT Pitfalls The classic verifier bugs and how to test for them: alg "none", algorithm confusion between RS256 and HS256, unvalidated kid values, weak secrets, and tokens that cannot be revoked.1 problem
- Bearer Tokens in Express Protect API routes with Authorization: Bearer tokens: a middleware that verifies and sets req.user, RFC 6750 error responses, and scope checks.1 problem
-
- Pro
Unit 5:Refresh Tokens and OAuth
Refresh token rotation with reuse detection, the authorization code flow with PKCE, and OpenID Connect sign-in.
- Refresh Tokens and Rotation Short-lived access tokens plus long-lived refresh tokens, stored hashed; rotation on every use, and reuse detection that revokes the whole token family.1 problem
- OAuth 2.0: Authorization Code with PKCE How "Sign in with ..." works: the authorization code flow, the state parameter, PKCE (code_verifier and S256 code_challenge), exact redirect URIs, and why the implicit flow is gone.1 problem
- Signing In with OpenID Connect OpenID Connect adds identity to OAuth: the ID token and what to check in it (signature, iss, aud, exp, nonce), the stable sub claim, and wiring /login and /callback in Express.1 problem
-
- Pro
Unit 6:Authorization
Roles and permissions, object-level checks against BOLA, and scoped API keys.
- Roles and Permissions Role-based access control: roles grant permissions, routes require permissions (not roles), deny by default, and role inheritance without surprises.1 problem
- Object-Level Authorization The most common API vulnerability: checking that a user may access this particular object (ownership, sharing, attributes), and building that check into the database query.1 problem
- Scoped API Keys Keys for machine clients: an identifiable prefix plus a random secret, stored hashed, limited by scopes, revocable, and checked without timing leaks.1 problem
-
- Pro
Unit 7:Abuse and Second Factors
Rate limiting, login throttling and lockout, HOTP and TOTP from the RFCs, and two-factor enrollment.
- Rate Limiting Fixed windows, sliding windows and token buckets; what to key limits on (IP, account, API key); 429 with Retry-After; and why limits belong in a shared store.1 problem
- Login Throttling and Lockout Slow down guessing against one account without handing attackers a denial-of-service switch: growing delays, NIST's cap of 100 consecutive failures, and generic responses.1 problem
- One-Time Codes: HOTP and TOTP How authenticator apps work: HOTP (RFC 4226) turns a shared secret and a counter into a short code with HMAC and dynamic truncation; TOTP (RFC 6238) uses the time as the counter.1 problem
- Enrolling and Verifying Two-Factor Codes Base32 secrets and otpauth:// URIs for authenticator apps, confirming enrollment with a first code, a verification window with replay protection, and recovery codes.1 problem
-
- Pro
Unit 8:Shipping Secure Auth
Secure defaults and audit logs, then the boss: a complete auth API on Express and MongoDB.
- Secure Defaults and Audit Logs The finishing layer: no-store and HSTS headers, generic errors, audit logs of security events that never contain secrets, and keeping signing keys out of the code.1 problem
- Boss: A Secure Auth API Combine the course in one Express and MongoDB service: NIST password rules, scrypt, enumeration-safe registration and login, throttling, hashed server-side sessions in __Host- cookies, origin checks and role-based admin routes.1 problem
-
Start Auth and API Security for free
Enroll for free and units 1 and 2 are yours. DevArcade Pro opens every unit of every course, including new ones as they launch, monthly or yearly.