JWT Auth API
A JWT auth API proves you understand authentication flow.
Routes
POST /auth/register
POST /auth/login
GET /auth/me
Register flow
- Validate name, email, password.
- Check if email already exists.
- Hash password.
- Save user.
- Return safe user data or token.
Never store plain text passwords.
Login flow
- Find user by email.
- Compare password with stored hash.
- Create JWT if valid.
- Return token or set cookie.
Protected route middleware
function requireAuth(req, res, next) {
const token = getTokenFromRequest(req)
if (!token) {
return res.status(401).json({ error: 'Unauthorized' })
}
req.user = verifyToken(token)
next()
}
Common mistake
Do not return password hash in API responses.
Even hashed passwords should stay server-side.
Interview angle
Explain register, login, password hashing, token generation, token verification middleware, protected routes, and safe response shape.