When signing into a third-party app with Google, the app never receives your Google password. Instead, Google grants an OAuth Authorization Code that is exchanged for a cryptographically signed JWT Access Token.
// Verify JWT Signature in Node.js Express Middleware
import jwt from 'jsonwebtoken';
function verifyToken(req: any, res: any, next: any) {
const authHeader = req.headers['authorization'];
const token = authHeader && authHeader.split(' ')[1]; // "Bearer <token>"
if (!token) return res.status(401).json({ error: 'Access Denied: Missing Token' });
try {
const decoded = jwt.verify(token, process.env.JWT_SECRET as string);
req.user = decoded; // Attach claims payload (userId, role)
next();
} catch (err) {
res.status(403).json({ error: 'Invalid or Expired Token' });
}
}Visual representation of control loops, memory layout, and execution flow for Authentication, Authorization, JWT & OAuth 2.0.
User submits credentials; server verifies hashed password in database.
Server creates a signed JWT containing Header, Payload (claims like userId, roles, exp), and Signature.
Client stores JWT (preferably in httpOnly Secure Cookie) and includes "Authorization: Bearer <token>" in API requests.
Resource server verifies JWT signature using public key or shared secret without database lookups.
| Feature / Dimension | Authentication (AuthN) | Authorization (AuthZ) |
|---|---|---|
| Primary Question | Who are you? (Identity verification) | What are you allowed to do? (Permission check) |
| Mechanisms | Passwords, Biometrics, OTP, 2FA, SAML, WebAuthn | RBAC (Role-Based Access Control), ABAC, OAuth 2.0 Scopes |
| Data Transmitted | ID Tokens (OpenID Connect) | Access Tokens (OAuth 2.0) |
Detailed answers, interviewer pro tips, key takeaway summaries, and code examples formulated for technical rounds.
✅ Correction: JWT payloads are only Base64 encoded, NOT encrypted! Anyone can decode the payload string. Only store non-sensitive claims like userId and role.
✅ Correction: This allows attackers to modify payloads, change the algorithm to "none", strip the signature, and bypass authentication checks. Always configure validation to require signing algorithms like HS256/RS256.
Standards for user identity verification and access authorization.