ContentsThe library

Proving Who You Are

The Token That Answers for Itself

Last timeNot Asking Again Every Time

A token can be a meaningless handle you look up, or a signed statement that answers the question by itself. The second is faster and cannot be taken back.

Handle or statement

The session identifier in the previous lesson was a handle. It is a long

random value that means nothing on its own; the meaning lives in your store,

and every request that carries it causes a lookup.

The alternative is to put the answer in the token. Instead of a random

string, the token is a short statement, something like this identity, these

permissions, issued at this time, valid until that time, with a

cryptographic seal attached. A receiver reads the statement, checks the seal

with a key it already has, and proceeds. It asks nobody anything.

FIG 1The two kinds, side by side
plaintext
a handle
  8f3c1a9e4b7d2056c8e1f4a7b9d3e6c0a2f5b8d1

  meaning: none, until the store is asked
  check:   one lookup, every request

a statement, decoded
  { sub: user-4417,
    scope: read write,
    iat: 1760000000,
    exp: 1760000900,
    iss: accounts.northwind,
    aud: billing-service }
  plus a seal over all of it

  meaning: carried with it
  check:   verify the seal, read the dates
The handle is forty characters of nothing. The statement is readable by anybody who holds it, which is the first thing to notice: the seal prevents alteration, not reading, so a self-contained token is a postcard rather than a letter.

The appeal is immediate. No lookup means no shared database between

services, no round trip on the hot path, and a service in another team can

accept your tokens knowing only a public key. For a system of twenty

services handling a lot of traffic, that is a genuine architectural

simplification rather than a micro-optimisation.

FIG 2How the two shapes differ
true of a handletrue of a signed statemeusually wantedthe reason people choose
needs a store on every r1010
readable by whoever hold0101
withdrawal takes effect 1010
verifiable by a service 0101
size grows with the perm1001
survives your database b0110
can be made longer-lived1010
The marked row is the one that decides most designs. Everything else on this list is a trade people are happy to make, and immediate withdrawal is the one property that tends to be non-negotiable once somebody asks what happens when an employee is dismissed.

What the seal actually proves

Be exact about this, because a great deal of confused design follows from

being loose about it.

A valid signature proves two things. It proves origin: this statement was

produced by somebody holding the signing key, which should be only you. And

it proves integrity: not one character has changed since it was signed, so a

holder cannot promote themselves by editing the scope.

It proves nothing else. In particular it does not prove that the statement

is still true. The account may have been deleted, the permission revoked,

the password changed after a breach, the subscription cancelled. The seal

was correct at the moment of issue and remains correct forever, because it

is a statement about the past.

The lesson stops here

4 more paragraphs to go

You have read the opening. The rest of the argument, the problems that check whether it landed, and the lines worth keeping at the end all come with a plan.

The first lesson of every course in the library reads the whole way through, free, so you can see exactly what the rest of them are.

See the planThe contents

This is the reading half

Starting the course gives you your own copy of it. Every idea on every page has problems standing under it, marked with a reason rather than a tick, and any sentence you do not believe can be opened and argued with. None of that can happen on a page nobody owns.

The contents

The rest of this course

  1. 01Who You Are, What You May Do, and Who Remembers
  2. 02What Each Kind of Proof Actually Resistsopening only
  3. 03The Thing the Browser Carriesopening only
  4. 04The Token That Answers for Itselfyou are here
  5. 05Two Tokens Beat Oneopening only
  6. 06Borrowing Somebody Elses Proofopening only
  7. 07The Request Your Browser Sent for Somebody Elseopening only
  8. 08Making Somebody Stop Being Signed Inopening only

Read alongside