# Course 37 - Building Web Apps with Ruby On Rails | Episode 14: From Basic HTTP to JWT Authentication Page: https://stenobird.com/podcast/cybercode-academy-7578615/course-37-building-web-apps-with-ruby-on-rails-episode-14-from-basic-http-to-jwt-authentication Text version: https://stenobird.com/podcast/cybercode-academy-7578615/course-37-building-web-apps-with-ruby-on-rails-episode-14-from-basic-http-to-jwt-authentication.md Podcast: [CyberCode Academy](https://stenobird.com/podcast/cybercode-academy-7578615) Published: 2026-06-27T06:00:06+00:00 Episode link: https://www.spreaker.com/episode/course-37-building-web-apps-with-ruby-on-rails-episode-14-from-basic-http-to-jwt-authentication--72405508 Audio file: https://dts.podtrac.com/redirect.mp3/api.spreaker.com/download/episode/72405508/from_basic_auth_to_stateless_jwt.mp3 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/cybercode-academy-7578615/episodes/course-37-building-web-apps-with-ruby-on-rails-episode-14-from-basic-http-to-jwt-authentication Duration seconds: 1174 ## Resource In this lesson, you’ll learn about: securing APIs in Rails, authentication strategies, and building a stateless authorization system1. Why API Security MattersUsing Ruby on Rails APIs:🔹 Problem: APIs are publicly exposed endpoints Without protection → anyone can access or manipulate data 🔹 Goal: Ensure only authorized users can interact with resources 👉 Key Insight An unsecured API is essentially a “wide-open backend”2. Foundation of API Design🔹 Core features: Multiple response formats (JSON) Pagination API versioning 🔹 Example:/api/v1/projects?page=1 👉 Key Insight Security must be designed alongside API structure—not added later3. Basic HTTP Authentication (Intro Level)🔹 Rails method:http_basic_authenticate_with name: "admin", password: "secret" 🔹 How it works: Sends username/password with every request 🔹 Problems: Credentials sent repeatedly Often stored or cached Vulnerable if not encrypted 👉 Key Insight Good for demos ❌ Not safe for production ❌4. Token-Based Authentication with JWTUsing JSON Web Token:🔹 Structure: Header Payload Signature 🔹 Example:xxxxx.yyyyy.zzzzz 🔹 Benefits: Stateless (no server session needed) Secure (signed token) Scalable 👉 Key Insight JWT is the industry standard for modern APIs5. Why JWT Is More Secure🔹 Advantages: No repeated credentials Token can expire Cannot be modified without secret key 🔹 Protection: Immune to CSRF (no cookies required) 👉 Key Insight Security comes from signature verification, not secrecy6. Implementing JWT in Rails🔹 Tool: JWT Ruby Gem 🔹 Encoding:JWT.encode(payload, secret_key) 🔹 Decoding:JWT.decode(token, secret_key) 👉 Key Insight The server is the only entity that can generate valid tokens7. Authentication Service🔹 Responsibilities: Handle signup Handle login Generate token 🔹 Flow: User logs in Server validates cre… ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/cybercode-academy-7578615/episodes/course-37-building-web-apps-with-ruby-on-rails-episode-14-from-basic-http-to-jwt-authentication/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/cybercode-academy-7578615/course-37-building-web-apps-with-ruby-on-rails-episode-14-from-basic-http-to-jwt-authentication.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.