Though many of the concepts in this course are still relevant, overall this course does not reflect our current course standards.

Check out a free preview of the full Secure Authentication for Web Apps & APIs Using JWTs course:
The "Securing the Payload" Lesson is part of the full, Secure Authentication for Web Apps & APIs Using JWTs course featured in this preview video. Here's what you'd learn in this lesson:

While answering a couple audience questions, Ryan takes some time to walk through how the server signs and secures the payload. He also talks about why sensitive data should not be stored in the payload and some strategies for storing the token secret in an environment variable.

Get Unlimited Access Now