Modern Authentication
Sessions, passkeys, delegated authorization, tokens, and single sign-on
Learn how modern login actually works, from session cookies and passkeys to OAuth delegation, PKCE, JWT validation, OpenID Connect, and single sign-on. Trace each flow across browser and server, understand the attacks each protocol binding blocks, and design token custody and session boundaries you can defend in a security review.
See the Invisible
Interactive simulators visualise what's hidden from view.
Hands-On Labs
Step through executions tick by tick. Manipulate state.
Why, Not Just What
Understand the reasoning behind every design decision.
Quizzes & Cheatsheets
Verify your understanding and keep a quick reference handy.
Get Certified
Earn a shareable certificate to prove your deep expertise.
What's Covered
Why stateless HTTP forces servers to keep login state, how session identifiers and cookie controls like HttpOnly and SameSite secure that state, and how WebAuthn replaces shared secrets with origin-bound public-key credentials that resist phishing.
The four OAuth roles and their artifacts, how the authorization code flow with PKCE splits work between the front channel and back channel, and how exact redirect matching and code verifiers keep interception from paying off.
The attack paths RFC 9700 was written to close, including code injection, mix-up, and open redirectors, plus the reasoning behind forbidding password grants and discouraging implicit token issuance as OAuth 2.1 consolidates the rules.
Short-lived access tokens, refresh-token rotation with replay detection, storage trade-offs under XSS and CSRF, and validating a JWT against an explicit trust context with issuer, audience, and algorithm checks that never confuse signing with secrecy.
How OpenID Connect layers identity onto OAuth, how ID Token validation and subject identifiers bind an external identity to a local account, and why independent identity-provider and relying-party sessions make logout propagation harder than login.
The Curriculum
Comprehensive Lessons! Each with theory, interactive simulation, and quiz.
Session Authentication and Cookie Security
Passkeys and WebAuthn Ceremonies
OAuth Roles and Delegated Authorization
Authorization Code Flow with PKCE
OAuth Threats and Security BCP Defenses
Token Lifecycles and Client-Specific Storage
JWT Structure and BCP Validation
OpenID Connect Identity and Local Login
Single Sign-On and Federated Session Boundaries
This course in one line
Stop configuring login flows you cannot explain
Ready to see what's really happening?
All courses included with your subscription. Cancel anytime.