Sessions, tokens, and what a JWT actually is
By the end of today you can explain how a stateless protocol remembers who you are, decode a JWT by hand, and say precisely why you cannot revoke one without giving up the property that made it attractive.
YesterdayOn Day 38 you decided who may do what. Today you learn how the server knows who is asking in the first place.
TomorrowTomorrow, the surrounding protections: how passwords are stored and why browsers restrict cross-origin requests.
Why this matters
Session and token choices are hard to reverse once users depend on them, and the tradeoff is genuinely subtle. Most people repeat advice here without understanding what they gave up.
- Sessions
- Tokens
- JWTs
- The revocation tradeoff
Learn it
75 minCopy this into Claude or ChatGPT. It quizzes you before it explains anything, which is deliberate. The resources under it are how you check what it told you.
Today's Master Prompt
Free · sign inA prompt written for this day alone: your level, the exact scope, what to leave out, and an instruction to quiz you before it explains anything. Paste it into Claude or ChatGPT and it teaches you today's material.
Check it against something that is not a model
An assistant can be fluent and wrong, and on a topic you met today you will not catch it. These cover the same ground and were made by people who do this for a living, so they are what you hold the explanation up against. They are other people's work and we only link to them, so judge them for yourself.
4 hand-picked resources
Free · sign inVideos, official docs and articles covering the same ground, each opened and annotated by hand. They are what you check the assistant against on a day you cannot yet catch it being wrong.
Build it
50 minDecode a JWT by hand using base64 decoding, without a library, and print its payload. Then add token-based authentication to your books API: a login endpoint that issues a signed token, and a dependency that verifies it. Then answer in writing: what would you have to build to log someone out immediately?
Recall it
20 minAnswer out loud, reveal, then mark honestly whether you had it. That score is the only thing on this page you do not get to choose.
5 recall questions
Free · sign inQuestions you answer from memory, then grade yourself against the real answer. The score is carried into the mastery rating below it, so an honest miss cannot quietly become a tick.
Rate it
Completion and mastery are tracked separately. Be honest, because an inflated rating only means the concept resurfaces sooner.
Mastery tracking
Free · sign inRate yourself against five named criteria per concept. Completion and mastery are tracked separately, and anything you rate shakily comes back automatically on a spaced schedule.
Recap
- 01Identity must travel with every request, because the protocol forgets
- 02A JWT is signed, not encrypted, and its payload is readable by anyone
- 03Sessions can be revoked because state exists; tokens cannot because it does not
- 04Refresh tokens are a compromise, not a solution
Your progress
Free · sign inMark days complete, pick up where you left off across devices, and watch completion and mastery diverge. Free, and the account exists only so ninety days of work cannot vanish with a cleared browser.
Zoom out
- The whole areaA software engineering roadmap that assumes you use AIWhat to learn in what order, and the mistakes that cost people months.
- Written upThe open redirect I shipped, and why the fix is four linesThis exact topic, gone wrong on this site, and what fixed it.
- Weighing it upHow this compares to freeCodeCampIncluding what freeCodeCamp does better, because some of it does.