0Pricing
Node.js Backend Development Bootcamp · Aula

Geração e validação de tokens JWT

Compreenda os JSON Web Tokens (JWT) e implemente sua geração e validação para garantir acesso seguro à API.

Geração e validação de tokens JWT é uma aula grátis de Node.js Backend Development Bootcamp no CoddyKit. Esta é a aula 2 de 6. Você pode ler a aula completa abaixo gratuitamente — depois pratica ao vivo no navegador com um editor de código integrado e um tutor de IA 24/7. Faz parte do caminho de aprendizado de Node.js Backend Development Bootcamp, e seu progresso é sincronizado entre a web e o app CoddyKit. O curso de Node.js Backend Development Bootcamp inclui 6 aulas no total.

Partes desta aula ainda não foram traduzidas e aparecem em inglês.

Intro to JWT: What & Why

Welcome! In this lesson, we'll dive into JSON Web Tokens (JWTs), a popular way to secure APIs.

A JWT is a compact, URL-safe means of representing claims to be transferred between two parties. Think of it as a digital ID card for your API.

Why Use JWTs for APIs?

JWTs offer several advantages for modern web and mobile APIs:

  • Statelessness: The server doesn't need to store session information. Each request carries the user's authentication details.
  • Scalability: Easier to scale applications horizontally as there's no shared session state across servers.
  • Security: If implemented correctly, JWTs provide a secure way to verify user identity and prevent tampering.

JWT Structure: Three Parts

A JWT is a string made of three parts, separated by dots (.). Each part is Base64Url-encoded:

HEADER.PAYLOAD.SIGNATURE

Let's break down what each of these parts means and why they're important for security.

The JWT Header

The Header typically consists of two parts:

  • alg (Algorithm): Specifies the cryptographic algorithm used for signing the token (e.g., HS256, RS256).
  • typ (Type): Indicates that the token is a JWT.

Example (Base64Url-decoded):

{"alg": "HS256", "typ": "JWT"}

The JWT Payload (Claims)

The Payload contains the "claims" – statements about an entity (like a user) and additional data.

Claims can be:

  • Registered: Standard fields like iss (issuer), exp (expiration time), sub (subject).
  • Public: Custom claims registered in the IANA JWT Registry.
  • Private: Custom claims agreed upon by the sender and receiver.

Example Payload:

{"sub": "user123", "name": "Alice", "exp": 1678886400}

The JWT Signature

The Signature is crucial for verifying the token's authenticity and integrity. It ensures the token hasn't been tampered with.

It's created by taking the encoded header, the encoded payload, a secret key, and the algorithm specified in the header, then signing them.

Formula (simplified):

HMACSHA256(encodedHeader + "." + encodedPayload, secretKey)

Python: Generating a JWT

Let's generate a JWT using Python's PyJWT library. First, install it: pip install PyJWT.

We define a payload with an expiration time and a secret key.

import jwt
import datetime

def main():
    SECRET_KEY = "your-super-secret-key"

    # Define payload with some claims
    payload = {
        "sub": "user123",
        "name": "Alice",
        "exp": datetime.datetime.utcnow() + datetime.timedelta(minutes=30),
        "iat": datetime.datetime.utcnow()
    }

    # Encode the token
    token = jwt.encode(payload, SECRET_KEY, algorithm="HS256")
    print(f"Generated JWT: {token}")

if __name__ == "__main__":
    main()

Secret Keys & Security

The SECRET_KEY used to sign and verify JWTs is extremely important. If this key is compromised, an attacker could forge valid tokens, granting unauthorized access.

  • Always use a strong, randomly generated key.
  • Never hardcode it in your application; use environment variables or a secure key management service.
  • Keep it absolutely confidential!

Python: Validating a JWT

To validate a JWT, you decode it using the same secret key and algorithm. PyJWT automatically verifies the signature and checks claims like expiration (`exp`).

import jwt
import datetime
import time

def main():
    SECRET_KEY = "your-super-secret-key"

    # Generate a token to validate (short expiry for demo)
    payload_gen = {
        "sub": "user123",
        "name": "Bob",
        "exp": datetime.datetime.utcnow() + datetime.timedelta(seconds=5), 
        "iat": datetime.datetime.utcnow()
    }
    token_to_validate = jwt.encode(payload_gen, SECRET_KEY, algorithm="HS256")
    print(f"Token to validate: {token_to_validate}\n")
    time.sleep(1) # Wait a bit for demonstration

    # Attempt to decode/validate it
    try:
        decoded_payload = jwt.decode(token_to_validate, SECRET_KEY, algorithms=["HS256"])
        print("Token is valid!")
        print(f"Decoded Payload: {decoded_payload}")
    except jwt.ExpiredSignatureError:
        print("Token has expired!")
    except jwt.InvalidTokenError:
        print("Invalid token (e.g., bad signature or format).")

if __name__ == "__main__":
    main()

JWT Best Practices

To keep your JWT implementation secure:

  • Set Expiration (exp): Always include an expiration claim to limit the window of a compromised token.
  • HTTPS: Always transmit JWTs over HTTPS to prevent eavesdropping.
  • Secure Storage: Store tokens securely on the client-side (e.g., HTTP-only cookies for web, secure storage for mobile).
  • Refresh Tokens: For long sessions, use short-lived access tokens and longer-lived refresh tokens.

Check Your Understanding

Review the components of a JWT. Which of the following parts is responsible for ensuring the token hasn't been tampered with?

Recap: JWT Essentials

In this lesson, we explored JSON Web Tokens (JWTs) for secure API authentication.

  • JWTs are compact, URL-safe tokens with a Header, Payload, and Signature.
  • The Header defines the token type and signing algorithm.
  • The Payload carries "claims" (data like user ID, roles, expiration).
  • The Signature verifies the token's integrity and authenticity.
  • We learned to generate and validate JWTs using Python's PyJWT library.
  • Always use strong, secret keys and set expiration times for security.

Next, we'll integrate JWTs into FastAPI using OAuth2 for a complete authentication flow!

Perguntas Frequentes

A aula “Geração e validação de tokens JWT” é grátis?

Sim — o texto completo de “Geração e validação de tokens JWT” é grátis para ler aqui na web. Para praticá-la interativamente (um editor de código integrado e um tutor de IA 24/7) e desbloquear o restante do curso de Node.js Backend Development Bootcamp, atualize para CoddyKit PRO. O curso de Node.js Backend Development Bootcamp inclui 6 aulas no total.

O que vou aprender em “Geração e validação de tokens JWT”?

Compreenda os JSON Web Tokens (JWT) e implemente sua geração e validação para garantir acesso seguro à API. Você pratica Node.js Backend Development Bootcamp com código prático que executa diretamente no navegador, e um tutor de IA 24/7 responde suas dúvidas enquanto trabalha na aula.

Preciso ter experiência prévia para começar Node.js Backend Development Bootcamp?

Nenhuma experiência prévia é necessária. Node.js Backend Development Bootcamp no CoddyKit é estruturado para alunos iniciantes até avançados, então você pode começar aqui ou desde o início e aprender no seu ritmo. Esta é a aula 2 de 6.

Quanto tempo leva a aula “Geração e validação de tokens JWT”?

A maioria das aulas CoddyKit leva cerca de 5–10 minutos. Cada uma é compacta e interativa, então você faz progresso constante e retoma exatamente de onde parou entre web e app.

Posso escrever e executar código nesta aula de Node.js Backend Development Bootcamp?

Sim. Cada aula de Node.js Backend Development Bootcamp inclui um editor de código integrado, então você escreve e executa código real direto no navegador e recebe feedback de IA instantaneamente — nenhuma configuração local necessária.

Todas as aulas deste curso

  1. Registo e Início de Sessão de Utilizadores
  2. Geração e validação de tokens JWT
  3. JWT para Autenticação sem Estado
  4. Integração do fluxo de senha do OAuth2
  5. Controlo de Acesso Baseado em Funções
  6. Controle de acesso baseado em funções (RBAC)
← Voltar para Node.js Backend Development Bootcamp