BackendAuthentication
JWT Tokens
JSON Web Token configuration and usage.
Configuration
SIMPLE_JWT = {
"AUTH_HEADER_TYPES": ("JWT",),
"ACCESS_TOKEN_LIFETIME": timedelta(hours=1),
"REFRESH_TOKEN_LIFETIME": timedelta(days=14),
"ROTATE_REFRESH_TOKENS": True,
"BLACKLIST_AFTER_ROTATION": True,
}| Setting | Value | Description |
|---|---|---|
AUTH_HEADER_TYPES | ("JWT",) | Use Authorization: JWT <token> header |
ACCESS_TOKEN_LIFETIME | 1 hour | How long an access token is valid |
REFRESH_TOKEN_LIFETIME | 14 days | How long a refresh token is valid |
ROTATE_REFRESH_TOKENS | True | Each refresh returns a new refresh token as well |
BLACKLIST_AFTER_ROTATION | True | The refresh token just used stops working (rest_framework_simplejwt.token_blacklist) |
A stolen access token is useful for an hour at most, and a refresh token works once. The frontend refreshes a minute before the access token expires, so people stay signed in for as long as they keep using the app within 14 days.
Endpoints
All JWT endpoints are under /auth/:
Obtain Token
POST /auth/jwt/create/Request:
{
"email": "user@example.com",
"password": "your-password"
}Response:
{
"access": "eyJ0eXAiOiJKV1Q...",
"refresh": "eyJ0eXAiOiJKV1Q..."
}Refresh Token
POST /auth/jwt/refresh/Request:
{
"refresh": "eyJ0eXAiOiJKV1Q..."
}Response:
{
"access": "eyJ0eXAiOiJKV1Q...",
"refresh": "eyJ0eXAiOiJKV1Q..."
}Store the new refresh token: the one you sent no longer works.
Verify Token
POST /auth/jwt/verify/Request:
{
"token": "eyJ0eXAiOiJKV1Q..."
}Returns 200 OK if valid, 401 Unauthorized if expired or invalid.
Usage
Include the JWT in the Authorization header for all API requests:
curl -H "Authorization: JWT eyJ0eXAiOiJKV1Q..." \
http://localhost:8000/api/workspaces/