Full lesson
Explore the full explanation, examples, and visuals at your own pace.
Maya signs in
Maya's password isn't what the database sends back. Her browser sends her email and password to the API, which finds her account in Users DB. The database returns a stored hash instead, giving the API something safer to verify than a readable password.
Verify without storing the password
The entered password and stored salted hash go into the hash verifier, which uses the hash’s parameters to check for a match. The server keeps the hash, not Maya’s plaintext password. If they don’t match, login stops here; no session is created.
A successful check creates a session
After the password check succeeds, the API creates a session that links Maya to an unpredictable session ID and saves it in the Session DB. It then sends that ID to the browser in a cookie. The cookie is a reference to her session, not her password.
The browser keeps the cookie for later requests.
The browser stores a session-ID cookie, not a password, and sends it on matching requests.
Maya opens her profile
When Maya opens her profile, the browser sends the cookie with the API request. The API uses its session ID to look up Maya’s session in the Session DB. If it’s valid, the API returns her profile data; if the session is missing or expired, it can’t authenticate this request.
After Maya logs in, what lets the API recognize her profile request?
Let's think this through. After Maya logs in, what lets the API recognize her profile request? A: The browser sends her password again. B: The cookie carries a session ID the API looks up. C: The browser compares her password hash. Choose an answer, or just think it through. I'll explain in a moment.
- The browser sends her password again
- The cookie carries a session ID the API looks up
- The browser compares her password hash
After Maya logs in, what lets the API recognize her profile request?
The answer is B: The cookie carries a session ID the API looks up. The browser sends its cookie with the profile request, and the API uses the session ID to find Maya's valid session. Her password was checked at login; it is not sent again for this request.
- The browser sends her password again
- The cookie carries a session ID the API looks up
- The browser compares her password hash
A token is another credential
A signed token is another credential the browser presents on each request. Unlike Maya’s session ID, the API validates the token’s signature instead of looking up server-side session state. It can still travel in a cookie, and validation permits access to Profile.
Keep credentials limited
Protect the session ID with HTTPS and secure cookie settings. Expiration and logout limit how long it grants access, while CSRF defenses address the fact that browsers send cookies automatically.
- Use HTTPS and secure cookie settings
- Set expiration and support logout
- Guard cookie-based requests against CSRF
Password once; session ID on later requests
A password establishes identity at login; later requests present a limited credential. Maya’s browser sends the session ID in its cookie, letting the API find her session and return her profile while it remains valid.




