{"id":3764,"date":"2026-10-02T12:00:46","date_gmt":"2026-10-02T05:00:46","guid":{"rendered":"https:\/\/sumberlaba.com\/index.php\/2026\/10\/02\/how-to-implement-jwt-authentication-in-node-js-a-step-by-step-tutorial\/"},"modified":"2026-10-02T12:00:47","modified_gmt":"2026-10-02T05:00:47","slug":"how-to-implement-jwt-authentication-in-node-js-a-step-by-step-tutorial","status":"publish","type":"post","link":"https:\/\/sumberlaba.com\/index.php\/2026\/10\/02\/how-to-implement-jwt-authentication-in-node-js-a-step-by-step-tutorial\/","title":{"rendered":"How to Implement JWT Authentication in Node.js: A Step-by-Step Tutorial"},"content":{"rendered":"<h1>How to Implement JWT Authentication in Node.js: A Step-by-Step Tutorial<\/h1>\n<p>JWT (JSON Web Token) authentication is a popular method for securing Node.js APIs. It allows stateless authentication by issuing signed tokens that clients send with each request. Unlike session-based auth, JWTs are self-contained and scalable.<\/p>\n<p>In this tutorial, you&#8217;ll learn how to set up JWT authentication in a Node.js Express app, from generating tokens to protecting routes. We&#8217;ll cover installation, token generation, middleware, and testing.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/sumberlaba.com\/wp-content\/uploads\/2026\/10\/article-1790917244288.jpg\" alt=\"Article illustration\" style=\"display:block;margin:20px auto;max-width:100%;height:auto;border-radius:8px;\" \/><\/p>\n<h2>1. Install Dependencies and Set Up Express<\/h2>\n<p>Start by initializing a Node.js project and installing the required packages: <code>express<\/code>, <code>jsonwebtoken<\/code>, and <code>bcrypt<\/code> for password hashing.<\/p>\n<ul>\n<li><code>npm init -y<\/code><\/li>\n<li><code>npm install express jsonwebtoken bcrypt<\/code><\/li>\n<\/ul>\n<p>Create a basic Express server with a secret key stored in an environment variable.<\/p>\n<h2>2. Generate and Sign JWT Tokens<\/h2>\n<p>When a user logs in, verify their credentials and generate a token using <code>jwt.sign()<\/code>. Include a payload like user ID and set an expiration time.<\/p>\n<ul>\n<li>Use <code>jwt.sign({ userId: user.id }, process.env.JWT_SECRET, { expiresIn: '1h' })<\/code>.<\/li>\n<li>Return the token to the client in the response.<\/li>\n<\/ul>\n<h2>3. Create Authentication Middleware<\/h2>\n<p>Write a middleware function to verify the token from the <code>Authorization<\/code> header. If valid, attach the decoded user to <code>req.user<\/code> and call <code>next()<\/code>.<\/p>\n<ul>\n<li>Extract token: <code>const token = req.headers.authorization?.split(' ')[1]<\/code>.<\/li>\n<li>Verify with <code>jwt.verify()<\/code> and handle errors.<\/li>\n<\/ul>\n<h2>4. Protect Routes and Test<\/h2>\n<p>Apply the middleware to protected routes. Use tools like Postman to test login and access with the token.<\/p>\n<ul>\n<li><code>app.get('\/protected', authenticate, (req, res) => res.json({ message: 'Access granted' }))<\/code>.<\/li>\n<li>Ensure tokens are sent in the <code>Authorization: Bearer &lt;token&gt;<\/code> format.<\/li>\n<\/ul>\n<p>That&#8217;s it! You&#8217;ve implemented JWT authentication in Node.js. Remember to keep your secret key safe and use HTTPS in production.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>How to Implement JWT Authentication in Node.js: A Step-by-Step Tutorial JWT (JSON Web Token) authentication is a popular method for securing Node.js APIs. It allows stateless authentication by issuing signed tokens that clients send with each request. Unlike session-based auth, JWTs are self-contained and scalable. In this tutorial, you&#8217;ll learn how to set up JWT &hellip; <\/p>\n","protected":false},"author":2716,"featured_media":3763,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-3764","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-non-category"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/sumberlaba.com\/index.php\/wp-json\/wp\/v2\/posts\/3764","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sumberlaba.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sumberlaba.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sumberlaba.com\/index.php\/wp-json\/wp\/v2\/users\/2716"}],"replies":[{"embeddable":true,"href":"https:\/\/sumberlaba.com\/index.php\/wp-json\/wp\/v2\/comments?post=3764"}],"version-history":[{"count":1,"href":"https:\/\/sumberlaba.com\/index.php\/wp-json\/wp\/v2\/posts\/3764\/revisions"}],"predecessor-version":[{"id":3765,"href":"https:\/\/sumberlaba.com\/index.php\/wp-json\/wp\/v2\/posts\/3764\/revisions\/3765"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/sumberlaba.com\/index.php\/wp-json\/wp\/v2\/media\/3763"}],"wp:attachment":[{"href":"https:\/\/sumberlaba.com\/index.php\/wp-json\/wp\/v2\/media?parent=3764"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sumberlaba.com\/index.php\/wp-json\/wp\/v2\/categories?post=3764"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sumberlaba.com\/index.php\/wp-json\/wp\/v2\/tags?post=3764"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}