jwt

5 posts.

5 min

Authorization Code and PKCE, by hand

Run the full browser flow with curl, inspect the tokens, rotate a refresh token, and watch PKCE reject a wrong verifier.

  • oauth2
  • pkce
4 min

ID tokens and UserInfo

Scope-aware identity claims in the ID token and the UserInfo endpoint, and a real OIDC flow to prove them.

  • oidc
  • jwt
4 min

Real tests and stable keys

Integration tests against real PostgreSQL with Testcontainers, and RSA signing keys that survive a restart.

  • testing
  • testcontainers
4 min

Revoking a JWT

Token revocation and introspection, and a filter that makes the management APIs reject a revoked JWT immediately.

  • oauth2
  • jwt
6 min

The mental model

OAuth roles, the Authorization Code flow, PKCE, the three kinds of token, and JWT signing, before any code.

  • oauth2
  • oidc