
Authentication
Course Index
29 Lessons · 3 Sections
Master web authentication — sessions, JWT, OAuth 2.0 with PKCE, OIDC, SSO/SAML, MFA/TOTP, Passkeys/WebAuthn & managed providers. Covers Auth0, Clerk & Supabase Auth. Includes 5 production builds from session auth to passwordless passkeys.
29Lessons
3Sections
5Projects
FreeAccess
Section 1Auth Fundamentals: Sessions, JWT & PasswordsLessons 1–10
Lesson 1
What is Authentication?
Lesson 2
Authentication vs Authorisation
Lesson 3
Session-Based Authentication
Lesson 4
Cookies: HTTPOnly & SameSite
Lesson 5
Token-Based Authentication
Lesson 6
JWT: Structure & Signing
Lesson 7
JWT: Access & Refresh Tokens
Lesson 8
JWT: Security Best Practices
Lesson 9
Password Hashing: Argon2id & bcrypt
Lesson 10
OAuth 2.0: The Authorization Framework
Section 2Modern Auth: OAuth2, SSO, MFA & PasskeysLessons 11–22
Lesson 11
OAuth 2.0: Authorization Code + PKCE
Lesson 12
OpenID Connect (OIDC)
Lesson 13
Social Login: Google & GitHub
Lesson 14
Single Sign-On (SSO)
Lesson 15
SAML 2.0: Enterprise SSO
Lesson 16
Multi-Factor Authentication (MFA)
Lesson 17
TOTP: Authenticator Apps
Lesson 18
Passkeys & WebAuthn / FIDO2
Lesson 19
Magic Links & Passwordless Auth
Lesson 20
Role-Based Access Control (RBAC)
Lesson 21
Auth Providers: Auth0, Clerk & Supabase
Lesson 22
API Key Authentication
Section 3Rate Limiting, NextAuth & ProjectsLessons 23–29