- Security
- Express
- JWT
JWT auth in Express, done right
Access and refresh tokens, httpOnly cookies, rate limiting and the small details that make authentication actually secure.
Talha Sajid8 min read
Almost every project I've built needed auth, and my first attempts stored tokens in localStorage. Here's the setup I use now.
Short-lived access, long-lived refresh
Access tokens live for minutes; refresh tokens live in an httpOnly, secure, same-site cookie and are rotated on every use.
The boring layers matter
Helmet, strict CORS, bcrypt with a sensible cost, input validation and rate limiting on login routes. None of it is exciting — all of it is necessary.