YOUR AUTH PATH
Learn with AI.
Verify before you trust it.
Who is calling, what they may do, and the concrete failures that show up when those checks are missing.
PHASE 01
Authentication Fundamentals
Identity versus permission, passwords, sessions, tokens, and a login.
PHASE 02
Modern Auth Patterns
OAuth with PKCE, passkeys, MFA, and the build-versus-buy choice.
PHASE 03
Authorization & API Security
Roles, scopes, ownership, and protected routes.
PHASE 04
Common Vulnerabilities & Defenses
OWASP in code, cookies, revocation, auth endpoints, and secrets.
1318 min1418 min1518 min1618 min1718 min
The real OWASP Top 10
After Protecting routes in practice
CSRF, XSS, and cookie security
After The real OWASP Top 10
Session fixation and token revocation
After CSRF, XSS, and cookie security
Rate limiting and user enumeration
After Session fixation and token revocation
Secrets management in depth
After Rate limiting and user enumeration
PHASE 05
Security as Practice
Dependencies, and review as a habit rather than a launch checklist.