HyperSaaS
BackendAuthentication

JWT Tokens

JSON Web Token configuration and usage.

Configuration

SIMPLE_JWT = {
    "AUTH_HEADER_TYPES": ("JWT",),
    "ACCESS_TOKEN_LIFETIME": timedelta(hours=1),
    "REFRESH_TOKEN_LIFETIME": timedelta(days=14),
    "ROTATE_REFRESH_TOKENS": True,
    "BLACKLIST_AFTER_ROTATION": True,
}
SettingValueDescription
AUTH_HEADER_TYPES("JWT",)Use Authorization: JWT <token> header
ACCESS_TOKEN_LIFETIME1 hourHow long an access token is valid
REFRESH_TOKEN_LIFETIME14 daysHow long a refresh token is valid
ROTATE_REFRESH_TOKENSTrueEach refresh returns a new refresh token as well
BLACKLIST_AFTER_ROTATIONTrueThe refresh token just used stops working (rest_framework_simplejwt.token_blacklist)

A stolen access token is useful for an hour at most, and a refresh token works once. The frontend refreshes a minute before the access token expires, so people stay signed in for as long as they keep using the app within 14 days.

Endpoints

All JWT endpoints are under /auth/:

Obtain Token

POST /auth/jwt/create/

Request:

{
  "email": "user@example.com",
  "password": "your-password"
}

Response:

{
  "access": "eyJ0eXAiOiJKV1Q...",
  "refresh": "eyJ0eXAiOiJKV1Q..."
}

Refresh Token

POST /auth/jwt/refresh/

Request:

{
  "refresh": "eyJ0eXAiOiJKV1Q..."
}

Response:

{
  "access": "eyJ0eXAiOiJKV1Q...",
  "refresh": "eyJ0eXAiOiJKV1Q..."
}

Store the new refresh token: the one you sent no longer works.

Verify Token

POST /auth/jwt/verify/

Request:

{
  "token": "eyJ0eXAiOiJKV1Q..."
}

Returns 200 OK if valid, 401 Unauthorized if expired or invalid.

Usage

Include the JWT in the Authorization header for all API requests:

curl -H "Authorization: JWT eyJ0eXAiOiJKV1Q..." \
  http://localhost:8000/api/workspaces/

On this page