Forem

# authentication

User authentication mechanisms

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
The Operational Cost of JWT Lifecycle Management: Overlooked Details

The Operational Cost of JWT Lifecycle Management: Overlooked Details

Comments
11 min read
JWT Refresh and Revocation Mechanisms: The State of Security Practices

JWT Refresh and Revocation Mechanisms: The State of Security Practices

Comments
10 min read
JWT Token Refresh Patterns in React 19: Avoiding the Silent Auth Death Spiral

JWT Token Refresh Patterns in React 19: Avoiding the Silent Auth Death Spiral

Comments
4 min read
Authentication Looks Easy - Until You Build It for Real Users
Cover image for Authentication Looks Easy - Until You Build It for Real Users

Authentication Looks Easy - Until You Build It for Real Users

Comments
5 min read
Authentication Processes are fighting human nature
Cover image for Authentication Processes are fighting human nature

Authentication Processes are fighting human nature

Comments
4 min read
DKIM, SPF & DMARC: The Complete Email Authentication Guide for 2026

DKIM, SPF & DMARC: The Complete Email Authentication Guide for 2026

Comments
6 min read
AWS IAM Deep Dive
Cover image for AWS IAM Deep Dive

AWS IAM Deep Dive

Comments
9 min read
JWT Hardening Checklist: Beyond 'Use HS256'

JWT Hardening Checklist: Beyond 'Use HS256'

Comments
6 min read
Passkey落地一周年:实测大规模采用的真实效果与遗留问题

Passkey落地一周年:实测大规模采用的真实效果与遗留问题

Comments
1 min read
JWT Storage: LocalStorage or HttpOnly Cookie?

JWT Storage: LocalStorage or HttpOnly Cookie?

1
Comments
9 min read
Why I stopped rolling my own auth and switched to Keycloak
Cover image for Why I stopped rolling my own auth and switched to Keycloak

Why I stopped rolling my own auth and switched to Keycloak

Comments
4 min read
How to handle hardware attestation without locking out real users
Cover image for How to handle hardware attestation without locking out real users

How to handle hardware attestation without locking out real users

Comments
5 min read
The 946-Millisecond Tax: Migrating API Key Auth from Bcrypt to HMAC-SHA256

The 946-Millisecond Tax: Migrating API Key Auth from Bcrypt to HMAC-SHA256

Comments
9 min read
Stop Storing JWTs in localStorage: A Security Guide for Web Developers
Cover image for Stop Storing JWTs in localStorage: A Security Guide for Web Developers

Stop Storing JWTs in localStorage: A Security Guide for Web Developers

1
Comments
3 min read
Laravel Now Has Native Passkeys: A Complete Guide to laravel/passkeys
Cover image for Laravel Now Has Native Passkeys: A Complete Guide to laravel/passkeys

Laravel Now Has Native Passkeys: A Complete Guide to laravel/passkeys

Comments
9 min read
👋 Sign in for the ability to sort posts by relevant, latest, or top.