Pembuatan dan Validasi Token JWT
Pahami JSON Web Token (JWT) dan implementasikan pembuatan serta validasinya untuk akses API yang aman.
Pembuatan dan Validasi Token JWT adalah pelajaran Node.js Backend Development Bootcamp gratis di CoddyKit. Ini adalah pelajaran 2 dari 6. Kamu bisa membaca pelajaran lengkapnya di bawah secara gratis — lalu praktikkan langsung di browser dengan editor kode bawaan dan tutor AI 24/7. Ini adalah bagian dari jalur belajar Node.js Backend Development Bootcamp, dan progresmu tersinkronisasi di web dan aplikasi CoddyKit. Kursus Node.js Backend Development Bootcamp mencakup 6 pelajaran total.
Bagian dari pelajaran ini belum diterjemahkan dan ditampilkan dalam bahasa Inggris.
Intro to JWT: What & Why
Welcome! In this lesson, we'll dive into JSON Web Tokens (JWTs), a popular way to secure APIs.
A JWT is a compact, URL-safe means of representing claims to be transferred between two parties. Think of it as a digital ID card for your API.
Why Use JWTs for APIs?
JWTs offer several advantages for modern web and mobile APIs:
- Statelessness: The server doesn't need to store session information. Each request carries the user's authentication details.
- Scalability: Easier to scale applications horizontally as there's no shared session state across servers.
- Security: If implemented correctly, JWTs provide a secure way to verify user identity and prevent tampering.
JWT Structure: Three Parts
A JWT is a string made of three parts, separated by dots (.). Each part is Base64Url-encoded:
HEADER.PAYLOAD.SIGNATURE
Let's break down what each of these parts means and why they're important for security.
The JWT Header
The Header typically consists of two parts:
alg(Algorithm): Specifies the cryptographic algorithm used for signing the token (e.g., HS256, RS256).typ(Type): Indicates that the token is a JWT.
Example (Base64Url-decoded):
{"alg": "HS256", "typ": "JWT"}The JWT Payload (Claims)
The Payload contains the "claims" – statements about an entity (like a user) and additional data.
Claims can be:
- Registered: Standard fields like
iss(issuer),exp(expiration time),sub(subject). - Public: Custom claims registered in the IANA JWT Registry.
- Private: Custom claims agreed upon by the sender and receiver.
Example Payload:
{"sub": "user123", "name": "Alice", "exp": 1678886400}The JWT Signature
The Signature is crucial for verifying the token's authenticity and integrity. It ensures the token hasn't been tampered with.
It's created by taking the encoded header, the encoded payload, a secret key, and the algorithm specified in the header, then signing them.
Formula (simplified):
HMACSHA256(encodedHeader + "." + encodedPayload, secretKey)Python: Generating a JWT
Let's generate a JWT using Python's PyJWT library. First, install it: pip install PyJWT.
We define a payload with an expiration time and a secret key.
import jwt
import datetime
def main():
SECRET_KEY = "your-super-secret-key"
# Define payload with some claims
payload = {
"sub": "user123",
"name": "Alice",
"exp": datetime.datetime.utcnow() + datetime.timedelta(minutes=30),
"iat": datetime.datetime.utcnow()
}
# Encode the token
token = jwt.encode(payload, SECRET_KEY, algorithm="HS256")
print(f"Generated JWT: {token}")
if __name__ == "__main__":
main()Secret Keys & Security
The SECRET_KEY used to sign and verify JWTs is extremely important. If this key is compromised, an attacker could forge valid tokens, granting unauthorized access.
- Always use a strong, randomly generated key.
- Never hardcode it in your application; use environment variables or a secure key management service.
- Keep it absolutely confidential!
Python: Validating a JWT
To validate a JWT, you decode it using the same secret key and algorithm. PyJWT automatically verifies the signature and checks claims like expiration (`exp`).
import jwt
import datetime
import time
def main():
SECRET_KEY = "your-super-secret-key"
# Generate a token to validate (short expiry for demo)
payload_gen = {
"sub": "user123",
"name": "Bob",
"exp": datetime.datetime.utcnow() + datetime.timedelta(seconds=5),
"iat": datetime.datetime.utcnow()
}
token_to_validate = jwt.encode(payload_gen, SECRET_KEY, algorithm="HS256")
print(f"Token to validate: {token_to_validate}\n")
time.sleep(1) # Wait a bit for demonstration
# Attempt to decode/validate it
try:
decoded_payload = jwt.decode(token_to_validate, SECRET_KEY, algorithms=["HS256"])
print("Token is valid!")
print(f"Decoded Payload: {decoded_payload}")
except jwt.ExpiredSignatureError:
print("Token has expired!")
except jwt.InvalidTokenError:
print("Invalid token (e.g., bad signature or format).")
if __name__ == "__main__":
main()JWT Best Practices
To keep your JWT implementation secure:
- Set Expiration (
exp): Always include an expiration claim to limit the window of a compromised token. - HTTPS: Always transmit JWTs over HTTPS to prevent eavesdropping.
- Secure Storage: Store tokens securely on the client-side (e.g., HTTP-only cookies for web, secure storage for mobile).
- Refresh Tokens: For long sessions, use short-lived access tokens and longer-lived refresh tokens.
Check Your Understanding
Review the components of a JWT. Which of the following parts is responsible for ensuring the token hasn't been tampered with?
Recap: JWT Essentials
In this lesson, we explored JSON Web Tokens (JWTs) for secure API authentication.
- JWTs are compact, URL-safe tokens with a Header, Payload, and Signature.
- The Header defines the token type and signing algorithm.
- The Payload carries "claims" (data like user ID, roles, expiration).
- The Signature verifies the token's integrity and authenticity.
- We learned to generate and validate JWTs using Python's
PyJWTlibrary. - Always use strong, secret keys and set expiration times for security.
Next, we'll integrate JWTs into FastAPI using OAuth2 for a complete authentication flow!
Pertanyaan yang Sering Diajukan
Apakah pelajaran “Pembuatan dan Validasi Token JWT” gratis?
Ya — teks lengkap “Pembuatan dan Validasi Token JWT” gratis dibaca di sini di web. Untuk praktiknya secara interaktif (editor kode bawaan dan tutor AI 24/7) dan buka sisa kursus Node.js Backend Development Bootcamp, upgrade ke CoddyKit PRO. Kursus Node.js Backend Development Bootcamp mencakup 6 pelajaran total.
Apa yang akan aku pelajari di “Pembuatan dan Validasi Token JWT”?
Pahami JSON Web Token (JWT) dan implementasikan pembuatan serta validasinya untuk akses API yang aman. Kamu berlatih Node.js Backend Development Bootcamp dengan kode praktik yang langsung kamu jalankan di browser, dan tutor AI 24/7 menjawab pertanyaanmu saat kamu mengerjakan pelajaran ini.
Apakah aku perlu pengalaman untuk memulai Node.js Backend Development Bootcamp?
Tidak diperlukan pengalaman sebelumnya. Node.js Backend Development Bootcamp di CoddyKit dirancang untuk pemula hingga pelajar tingkat lanjut, jadi kamu bisa memulai di sini atau dari awal dan belajar sesuai kecepatan kamu sendiri. Ini adalah pelajaran 2 dari 6.
Berapa lama pelajaran “Pembuatan dan Validasi Token JWT” memakan waktu?
Sebagian besar pelajaran CoddyKit memakan waktu sekitar 5–10 menit. Setiap pelajaran ringkas dan interaktif, jadi kamu membuat kemajuan stabil dan melanjutkan dari tempat kamu tinggalkan di web dan aplikasi.
Bisakah aku menulis dan menjalankan kode dalam pelajaran Node.js Backend Development Bootcamp ini?
Ya. Setiap pelajaran Node.js Backend Development Bootcamp menyertakan editor kode bawaan, jadi kamu menulis dan menjalankan kode nyata langsung di browser dan mendapatkan umpan balik AI instan — tidak diperlukan penyiapan lokal.
Semua pelajaran dalam kursus ini
- Pendaftaran & Login Pengguna
- Pembuatan dan Validasi Token JWT
- JWT untuk Autentikasi Tanpa Status
- Integrasi Alur Kata Sandi OAuth2
- Kontrol Akses Berbasis Peran
- Kontrol Akses Berbasis Peran (RBAC)