Week 6: Authentication with OAuth2 & JWT

Build the next production-ready layer of your FastAPI service through clear concepts, a focused implementation and a practical exercise.

Module 5 of 12Week 6 of 15~3-4 HoursHands-on Exercise Included

By the end of this week, you'll be able to

  • Secure password hashing
  • OAuth2 password flow
  • Short-lived signed access tokens

1. Secure password hashing

Start with the contract: make inputs, outputs and failure behavior explicit before adding infrastructure. This keeps the feature easy to reason about and gives tests a stable boundary.

2. OAuth2 password flow

Apply the pattern through a small vertical slice. Keep framework wiring at the edge and business decisions in focused functions or services that can be tested without starting the whole application.

core example
from datetime import datetime, timedelta, timezone
import jwt

def create_access_token(user_id: int) -> str:
    payload = {"sub": str(user_id), "exp": datetime.now(timezone.utc) + timedelta(minutes=15)}
    return jwt.encode(payload, settings.jwt_secret, algorithm="HS256")

3. Short-lived signed access tokens

Treat failure paths as part of the design. Add bounded resource usage, meaningful errors and a verification step so the behavior remains dependable under real production conditions.

4. Hands-on Exercise

Build the feature

Implement registration, login and a protected /users/me endpoint. Store only password hashes and reject expired or invalid tokens.

Definition of done

  • The happy path works through the real HTTP boundary.
  • At least one failure path is handled and tested.
  • Configuration and secrets stay outside source code.
  • The README explains how to run and verify the result.

5. Knowledge Check

Why must JWT payloads never contain secrets?

Show answer

A JWT is signed, not encrypted; clients can decode its payload even though they cannot safely alter it.