All posts
  • Security
  • Express
  • JWT

JWT auth in Express, done right

Access and refresh tokens, httpOnly cookies, rate limiting and the small details that make authentication actually secure.

Talha Sajid8 min read

Almost every project I've built needed auth, and my first attempts stored tokens in localStorage. Here's the setup I use now.

Short-lived access, long-lived refresh

Access tokens live for minutes; refresh tokens live in an httpOnly, secure, same-site cookie and are rotated on every use.

The boring layers matter

Helmet, strict CORS, bcrypt with a sensible cost, input validation and rate limiting on login routes. None of it is exciting — all of it is necessary.