Course

Modern Authentication

Sessions, passkeys, delegated authorization, tokens, and single sign-on

Learn how modern login actually works, from session cookies and passkeys to OAuth delegation, PKCE, JWT validation, OpenID Connect, and single sign-on. Trace each flow across browser and server, understand the attacks each protocol binding blocks, and design token custody and session boundaries you can defend in a security review.

Latest Updates 2026

See the Invisible

Interactive simulators visualise what's hidden from view.

Hands-On Labs

Step through executions tick by tick. Manipulate state.

Why, Not Just What

Understand the reasoning behind every design decision.

Quizzes & Cheatsheets

Verify your understanding and keep a quick reference handy.

Get Certified

Earn a shareable certificate to prove your deep expertise.

What's Covered

Sessions, cookies, and passkeys

Why stateless HTTP forces servers to keep login state, how session identifiers and cookie controls like HttpOnly and SameSite secure that state, and how WebAuthn replaces shared secrets with origin-bound public-key credentials that resist phishing.

OAuth delegation and the code flow

The four OAuth roles and their artifacts, how the authorization code flow with PKCE splits work between the front channel and back channel, and how exact redirect matching and code verifiers keep interception from paying off.

Threats and the Security BCP

The attack paths RFC 9700 was written to close, including code injection, mix-up, and open redirectors, plus the reasoning behind forbidding password grants and discouraging implicit token issuance as OAuth 2.1 consolidates the rules.

Token lifecycles and JWT validation

Short-lived access tokens, refresh-token rotation with replay detection, storage trade-offs under XSS and CSRF, and validating a JWT against an explicit trust context with issuer, audience, and algorithm checks that never confuse signing with secrecy.

Federated identity and single sign-on

How OpenID Connect layers identity onto OAuth, how ID Token validation and subject identifiers bind an external identity to a local account, and why independent identity-provider and relying-party sessions make logout propagation harder than login.

The Curriculum

Comprehensive Lessons! Each with theory, interactive simulation, and quiz.

Session Authentication and Cookie Security

Passkeys and WebAuthn Ceremonies

OAuth Roles and Delegated Authorization

Authorization Code Flow with PKCE

OAuth Threats and Security BCP Defenses

Token Lifecycles and Client-Specific Storage

JWT Structure and BCP Validation

OpenID Connect Identity and Local Login

Single Sign-On and Federated Session Boundaries

This course in one line

Stop configuring login flows you cannot explain

Ready to see what's really happening?

All courses included with your subscription. Cancel anytime.