Back to explore
BackendSystem flow4 min

Authenticated API requests

Token validation, permissions, and the work behind a protected endpoint.

Process overview

Conceptual illustration for Authenticated API requests
  1. Request
  2. Validate
  3. Authorize
  4. Execute
  5. Respond

Steps

5 steps

A request arrives with a credential

The client sends a request to a protected endpoint. In this example, its Authorization header carries an access token intended for this API.

The API validates the token

For a JWT access token, the API checks the signature and standard claims, including expiration. Reading a token’s payload alone does not prove authenticity.

Identity becomes a permission check

The API verifies that the audience matches and the token has the required permissions. A valid token does not automatically grant every action.

The handler does the work

After access checks pass, application code handles the request. It can read data, run business rules, or call another service.

The result travels back

The API returns the result and an HTTP status. A failed credential check stops the request before the protected operation runs.

Scope

A simplified JWT protected API request. Session cookies, opaque tokens, and application specific authorization use different details.

Source

Auth0 · Validate access tokens(opens in a new tab)
Saved explanations