What is the difference between JWT and session-based authentication?
Quick answer
Session authentication stores the login state on the server and gives the browser a session ID cookie, while JWT authentication gives the client a signed token that contains the user's claims so the server can verify it without storing state.
Sessions are simple and easy to revoke: delete the server-side record and the user is logged out immediately, but you need shared storage such as Redis once you run several servers. A JWT is self-contained and works well across services, but you cannot invalidate a single token before it expires unless you keep a deny list or use short lifetimes with refresh tokens.
Whichever you pick, store tokens in HttpOnly, Secure, SameSite cookies rather than localStorage to limit XSS risk, hash passwords with bcrypt or Argon2, use short access-token lifetimes, and verify the signature algorithm explicitly. Authentication confirms who you are; authorisation decides what you may do.
Key points
- Session: state on the server, easy to revoke
- JWT: stateless, hard to revoke before expiry
- Use HttpOnly Secure cookies and short token lifetimes