Security & Token Handling
Secrets, JWT safety, refresh token flow.
Token Types
Access Token
Refresh Token
Where to Store Tokens
Mobile Apps (iOS / Android)
Web Apps
Access token → in memory or encrypted local storage
Refresh token → HTTP-only secure cookie (server-set)
Backend or Server-Side Apps
Refreshing Access Tokens
Avoid “silent refresh loops”
Session Expiry & Logout
Preventing Token Exposure
Do NOT:
DO:
Handling Token Compromise
Common Security Patterns (Recommended)
Pattern 1 — Mobile App
Pattern 2 — Web App with Backend
Pattern 3 — Server-to-Server Integration
Summary
Last updated

