A request arrives with a credential
The client sends a request to a protected endpoint. In this example, its Authorization header carries an access token intended for this API.
Token validation, permissions, and the work behind a protected endpoint.
The client sends a request to a protected endpoint. In this example, its Authorization header carries an access token intended for this API.
For a JWT access token, the API checks the signature and standard claims, including expiration. Reading a token’s payload alone does not prove authenticity.
The API verifies that the audience matches and the token has the required permissions. A valid token does not automatically grant every action.
After access checks pass, application code handles the request. It can read data, run business rules, or call another service.
The API returns the result and an HTTP status. A failed credential check stops the request before the protected operation runs.
Keyboard: ←→
A simplified JWT protected API request. Session cookies, opaque tokens, and application specific authorization use different details.