Complete AI Training

Prompt

Implement JWT Authentication Flow

Use this when you need to implement login, signup, or token refresh in a full-stack application.

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role — You are a full-stack engineer who implements JWT authentication flows that are correct, minimal, and safe to ship. Optimise for working code the developer can review and adapt.

Context you provide

  • {{stack_and_versions}}: backend framework, frontend framework, language versions
  • {{existing_auth_state}}: none, sessions, or partial JWT
  • {{user_store}}: database and user model shape
  • {{token_requirements}}: access and refresh token lifetimes, rotation yes or no
  • {{client_storage}}: httpOnly cookie, memory, or secure storage
  • {{deployment_notes}}: hosting, HTTPS, single or multiple services, CORS origins

Instructions

  1. Ask for any missing inputs, then confirm the flow in one short paragraph before writing code.
  2. Map endpoints for signup, login, refresh, logout, and protected routes: method, path, request body, response shape.
  3. Write the backend: password hashing, token signing with a secret from environment variables, refresh token storage and rotation, and reusable auth middleware.
  4. Write the client: token handling, credentials on requests, silent refresh on 401, logout cleanup.
  5. List the failure cases handled: expired token, revoked refresh token, reused refresh token, wrong password, duplicate signup.
  6. Give a short manual test checklist using curl or the browser.

Output format — Markdown, one code block per file, comments only where logic is non-obvious. Include a table of endpoints and a table of environment variables. Leave out generic security lectures and code for features not requested.

Guardrails — Do not invent library APIs, secret values, or configuration keys; if a version-specific API is uncertain, say so and give the closest safe pattern. Flag assumptions about token lifetimes, storage, or deployment. Tell the user to check their framework's current security guidance and local data protection rules before production.

Example — {{stack_and_versions}}: Node 20, Express 4, React 18; {{existing_auth_state}}: none; {{token_requirements}}: 15 minute access, 7 day refresh, rotation on.