API Authentication: Sessions, Tokens & Rotation
Authentication is the process of verifying who a client or user is. In modern web and API architecture, choosing the right authentication strategy—Stateful Cookie Sessions vs Stateless Bearer Tokens vs API Keys—determines system scalability, cross-domain capabilities, and security posture.
┌─────────────────────────────────────────────────────────────┐
│ Session vs Token Authentication │
├──────────────────────────────┬──────────────────────────────┤
│ Stateful Session Auth │ Stateless Token Auth (JWT) │
├──────────────────────────────┼──────────────────────────────┤
│ 1. User logs in. │ 1. User logs in. │
│ 2. Server creates session in │ 2. Server signs JWT token │
│ Redis/DB & returns Cookie.│ and returns to client. │
│ 3. Client transmits Cookie. │ 3. Client sends Bearer token.│
│ 4. Server looks up session ID│ 4. Server verifies signature │
│ in Redis on EVERY call. │ cryptographically (0 DB). │
└──────────────────────────────┴──────────────────────────────┘
1. Access Tokens & Refresh Tokens
In token-based architectures, using a single long-lived access token is dangerous (if stolen, an attacker has permanent access). Instead, use a Dual-Token Architecture:
- Access Token (Short-Lived: 15 Minutes):
- Stateless JWT passed in
Authorization: Bearer <token>. - Used to authorize everyday API requests.
- Stateless JWT passed in
- Refresh Token (Long-Lived: 7–30 Days):
- Stored in a secure,
HttpOnly,Securecookie. - Sent only to
/api/auth/refreshto request a new short-lived access token.
- Stored in a secure,
2. Refresh Token Rotation
To protect against token theft, enterprise systems implement Refresh Token Rotation:
- Every time a refresh token is used to obtain a new access token, the server invalidates the old refresh token and issues a brand-new one.
- If an attacker attempts to replay an already-used refresh token, the server detects the breach, immediately revokes the entire token family, and logs out the user!
Summary & Key Takeaways
- Stateful sessions require central database lookups; stateless tokens verify cryptographically.
- Dual-token architecture pairs short-lived access tokens with secure refresh tokens.
- Refresh token rotation detects and neutralizes stolen token replay attacks.
Best Practices & Senior Guidance
- Never Store Access Tokens in
localStorage: Tokens inlocalStorageare vulnerable to XSS theft; keep access tokens in JavaScript memory and refresh tokens inHttpOnlycookies. - Keep Access Token Lifespans Short (15 min): Minimizes the vulnerability window if a token is intercepted.