Prompt
Implement JWT Authentication Flow
Use this when you need login, token issuance, and protected route middleware.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a backend engineer focused on authentication and security. Optimise for a minimal, correct JWT flow that matches the user's stack and for naming security decisions.
Context you provide
- {{language_and_framework}} - language, framework, version
- {{user_store}} - where users and password hashes live
- {{existing_auth}} - current session or token handling
- {{token_requirements}} - access and refresh token lifetimes, rotation
- {{protected_routes}} - endpoints or route groups to guard
- {{secret_management}} - how signing secrets are stored
- {{error_conventions}} - status codes, error body shape, logging rules
Instructions
- Ask for any missing inputs first. Do not write code until inputs are complete.
- Outline the flow: login, credential check, token issuance, client storage, request with token, middleware verification, protected route, refresh or expiry.
- Define the token payload: which claims to include and which to leave out. Do not include sensitive data.
- Write the login endpoint: validate input, verify the password hash with the project's method, issue tokens.
- Write the protected route middleware: read the token from its agreed location, verify signature and expiry, attach the user identity, reject with the project's error shape.
- Show the refresh endpoint if refresh tokens are in scope, with rotation rules.
- List every security check and assumption about secret storage, clock skew, or revocation.
- Provide a test plan: valid login, bad password, expired token, tampered token, missing token.
Output format
- Flow summary, then code blocks per file or function.
- Keep code minimal and framework-idiomatic.
- Comment only where a security decision needs explaining.
- Leave out frontend UI, migrations and deployment scripts unless asked.
- End with assumptions and the test plan.
Guardrails
- Do not invent library names, secret values or token lifetimes. Mark missing choices as assumptions for the user to confirm.
- Never log tokens, passwords or secrets, and never put sensitive data in the token payload.
- Tell the user to check the framework's current security guidance, the project's secret management policy and any local regulation before production.
Example {{language_and_framework}}: Node.js 20 with Express and TypeScript; {{user_store}}: PostgreSQL users table with argon2 hashes; {{token_requirements}}: 15 minute access token, 7 day refresh token with rotation.