> For the complete documentation index, see [llms.txt](https://program.hackyourfuture.dk/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://program.hackyourfuture.dk/course-content/backend/node/week3.md).

# Week 3

In this session we will focus on securing our existing Snippets API. We will explore different ways of authenticating users and protecting API endpoints, and compare their trade-offs so you can choose the right approach for different scenarios.

## Contents

* [Preparation](/course-content/backend/node/week3/preparation.md)
* [Session Plan](/course-content/backend/node/week3/session-plan.md) (for mentors)
* [Assignment](/course-content/backend/node/week3/assignment.md)

## Session Learning goals

By the end of this session, you will be able to:

* [ ] Explain why storing plaintext passwords is insecure and how hashing (e.g. with bcrypt) improves security.
* [ ] Implement a basic login flow for the Snippets API using securely stored passwords.
* [ ] Protect Snippets API endpoints using JWT-based stateless authentication.
* [ ] Protect Snippets API endpoints using session-based authentication with cookies.
* [ ] Describe when to use database-stored tokens and API keys, and understand their trade-offs.
* [ ] Compare the strengths and weaknesses of credentials-only, DB tokens, JWT, sessions, and API keys for different use cases.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://program.hackyourfuture.dk/course-content/backend/node/week3.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
