9 Serveless and JWT

Mehul Patel


core concepts

  • function
  • event
  • services


  • Authorization what you can do 授权
  • Authentication who you are 认证

JSON Web Token

3 JWAT Attacting JWT

  • a way to encode information
  • securely communicate JSON objects
  • secret based verification
  • self contained

OAuth 2.0

user gain access without giving them passwords


  • resource owner, normally end user
  • resource server, the api you want to access
  • client, the app requesting accer to a protected resurce on bahalf of the resource owner
  • authorization server, like Auth0

Protocol flow (in picture)


  • App =Auth0 + Serverless Platform
  • webtask.io