Profile    Mohammed Shiroz Status   Loading  
Logo
Share This

My authentication
blog and Updates

It's my personal blog and my post about what was my interested in. Not regularly. If you have any questions any discussion, I'm happy you get in touch with me, and try to answer as many as possible!

Blog
Let's See
Back to blog
Filter by:
Tags
//Article

JWT vs Sessions vs API Keys: Which One to Use, and When

JWT vs Sessions vs API Keys: Which One to Use, and When

Blog Summary

"We use JWT" is often the answer for the web app, the mobile app and the partner integration alike. Sessions, JWTs and API keys solve different problems; here's how to tell which one each caller needs.

Read more
  • 111
  • 52
  • 12

Passkeys Explained: Is This Finally the End of Passwords?

Passkeys Explained: Is This Finally the End of Passwords?

Blog Summary

Passkeys can't be phished, reused or leaked from your database, and users log in with a fingerprint. So why do most sites still ask for a password? How passkeys work, what WebAuthn looks like in code, and the parts nobody mentions.

Read more
  • 96
  • 63
  • 15

Two-Factor Authentication: How Those Six-Digit TOTP Codes Actually Work

Two-Factor Authentication: How Those Six-Digit TOTP Codes Actually Work

Blog Summary

Your authenticator app and the server agree on the same six digits with no network at all. Here's the shared secret, the 30-second clock and the HMAC behind it, plus where 2FA is strong and where it isn't.

Read more
  • 34
  • 87
  • 24

OAuth 2.0 Explained Without the Jargon: The Valet Key Guide

OAuth 2.0 Explained Without the Jargon: The Valet Key Guide

Blog Summary

OAuth is a valet key for your data: it lets an app park the car without reading your mail. The authorization code flow with PKCE explained step by step, plus scopes, tokens and OAuth vs OpenID Connect.

Read more
  • 84
  • 22
  • 22

JWT Explained: What's Inside the Token and What Can Go Wrong

JWT Explained: What's Inside the Token and What Can Go Wrong

Blog Summary

Paste any JWT into a decoder and you can read it, no key needed. That surprises a lot of developers. Here's what's really inside a token, why base64 isn't encryption, and the mistakes that cause real breaches.

Read more
  • 31
  • 77
  • 25

Cookies vs Tokens: Where Should Your Web App Keep the Session?

Cookies vs Tokens: Where Should Your Web App Keep the Session?

Blog Summary

That login token in localStorage is readable by every script on your page. Here's the real trade-off between HttpOnly cookies and tokens, XSS vs CSRF, and how Laravel Sanctum handles SPAs and mobile apps.

Read more
  • 81
  • 78
  • 13

01. About Shiroz

Mohammed Shiroz

Hi, I'm Mohammed Shiroz, a software engineer and AI enthusiast from Sri Lanka who turns ideas into intelligent, real-world solutions. With over 9 years of hands-on experience, I currently lead real estate ERP development at Kate Group, a...

03.My Projects

04. Categories

Ready To Start Your Project ?

Get in Touch
Close