HTHyperTransformer AI

Study cards › Security

SecurityInterview questions and answers

← Topics1 / 100
1 / 100 viewed
Question

What is JWT?

Answer

JSON Web Token — a base64-encoded JSON payload signed (HMAC or RSA/ECDSA) so the server can verify the token's authenticity without a database lookup. Used to authenticate API requests statelessly. Anyone can READ a JWT's contents (base64 isn't encryption); only signing key holders can produce valid ones.

Question

Structure of a JWT?

Answer

Three dot-separated parts: header.payload.signature. Header declares the signing algorithm; payload contains claims (user id, expiry, roles); signature is computed over header+payload using the secret. Headers and payload are base64-encoded JSON — readable by anyone.

Question

Signed vs encrypted JWT?

Answer

Signed (JWS): readable by anyone, but tamper-evident — anyone can verify the signature with the public key. Encrypted (JWE): payload is also kept confidential. Most apps use signed JWTs; only use JWE when the token's contents themselves must be hidden from intermediaries.

Question

Where should you store a JWT on the client?

Answer

An HTTP-only, Secure cookie is the safest — JavaScript can't read it, so XSS can't steal it. Avoid localStorage if XSS is a concern. Never store JWTs anywhere a third-party script could read them. Pair with SameSite=Lax/Strict to mitigate CSRF.

Question

Why use short-lived access tokens?

Answer

If an access token leaks, a short expiry (5-15 min) limits how long attackers can use it. Pair with a refresh token (longer-lived, stored more securely) that gets new access tokens silently. The pattern gives you both UX (no constant logins) and security (small blast radius).

95 more Security cards

Sign in with Google to study the whole deck, flag tricky answers and track your progress.

Continue with Google

More topics: React & Frontend JavaScript & TypeScript Backend Engineering Databases System Design AI & Agentic AI DevOps & Cloud Testing DSA Coding Problems (Python)