P
💻DeveloppementIntermediateAll AIs

Prompt to Create a Complete JWT Authentication System

A complete prompt to generate a secure JWT authentication system with token management, refresh tokens, middleware and security best practices.

Paste in your AI

Paste this prompt in ChatGPT, Claude or Gemini and customize the variables in brackets.

Tu es un développeur backend senior spécialisé en sécurité applicative. Conçois un système d'authentification JWT complet pour une application [LANGAGE/FRAMEWORK] avec les spécifications suivantes :

  1. Architecture du système :

    • Endpoint d'inscription avec validation des données (email, mot de passe fort)
    • Endpoint de connexion retournant un access token et un refresh token
    • Endpoint de rafraîchissement du token
    • Endpoint de déconnexion avec invalidation du token
    • Middleware d'authentification pour protéger les routes
  2. Sécurité obligatoire :

    • Hashage des mots de passe avec bcrypt (salt rounds configurable)
    • Access token courte durée ([DUREE_ACCESS_TOKEN]) et refresh token longue durée ([DUREE_REFRESH_TOKEN])
    • Stockage sécurisé des refresh tokens en base de données avec possibilité de révocation
    • Protection contre les attaques par force brute (rate limiting)
    • Rotation des refresh tokens à chaque utilisation
    • Validation stricte du payload JWT
  3. Structure attendue :

    • Modèle utilisateur avec les champs nécessaires
    • Service d'authentification séparé de la logique des contrôleurs
    • Gestion centralisée des erreurs (token expiré, invalide, utilisateur non trouvé)
    • Variables d'environnement pour les secrets et la configuration
    • Types/interfaces si le langage le permet
  4. Base de données : [TYPE_BASE_DE_DONNEES]

  5. Bonus :

    • Tests unitaires pour les fonctions critiques (génération token, vérification, hashage)
    • Documentation des endpoints au format OpenAPI/Swagger
    • Exemple de route protégée avec extraction des données utilisateur depuis le token

Fournis le code complet, commenté en français, avec les commandes d'installation des dépendances nécessaires. Explique chaque choix de sécurité.

Personalize this prompt with Léa

Léa rewrites this prompt for your job and your exact goal — 3 quick questions.

Why this prompt works

<p>This prompt guides AI to produce a professional and secure JWT authentication system. By specifying your <strong>language or framework</strong> (Node.js/Express, Python/FastAPI, Java/Spring Boot, etc.), <strong>token duration</strong> and <strong>database type</strong>, you get code tailored to your exact tech stack.</p><p>The prompt structure enforces a layered architecture (controllers, services, middleware) that reflects industry best practices. The security requirements — refresh token rotation, rate limiting, bcrypt hashing — ensure the generated code goes beyond a basic example and constitutes a solid foundation for production.</p><p><strong>Usage tips</strong>: start by replacing the bracketed variables, then iterate. Next, ask the AI to add features like <strong>two-factor authentication</strong>, <strong>role management</strong> (RBAC), or integration with an <strong>OAuth provider</strong> (Google, GitHub). You can also request an adaptation for a microservices architecture with a centralized authentication service.</p>

Use Cases

Create REST API authentication from scratchSecure an existing application by replacing sessions with JWTsSet up a fullstack project with complete user managementLearn JWT security best practices by example

Expected Output

A complete authentication system with commented source code: user model, authentication service, controllers for signup/login/refresh/logout, route protection middleware, configuration file, installation commands and unit tests.

Improve this prompt

Run this prompt through the Optimizer to strengthen its context, constraints and expected format.

Improve this prompt with the Optimizer

Comments

  • LéaAI

    Pour un résultat plus précis, remplacez [LANGAGE/FRAMEWORK] et [TYPE_BASE_DE_DONNEES] par des valeurs concrètes (ex. Node.js/Express + PostgreSQL) et ajoutez des exigences de sécurité : stockage des refresh tokens avec un identifiant unique (jti) et date d’expiration en base, révocation explicite, et envoi du refresh token dans un cookie HttpOnly (jamais en localStorage) pour limiter les risques XSS.

📬 Get new prompts every week

Join our newsletter and never miss a prompt.

Go further

Similar Prompts

💻DeveloppementAdvancedAll AIs

Prompt to Create a Monorepo with Turborepo

A prompt to generate the complete architecture of a Turborepo monorepo with folder structure, pipelines, shared packages and CI/CD configuration.

0179
💻DeveloppementIntermediateAll AIs

Mistral Prompt for Creating a Software Architecture

Mistral, the leading French AI model, excels in designing software architectures thanks to its deep understanding of design patterns and technical constraints. Whether you're starting a new project or restructuring an existing application, Mistral can help you define a solid, scalable, and maintainable architecture. By providing a well-structured prompt, you will get detailed recommendations on architectural pattern choices, separation of concerns, appropriate technologies, and inter-service communication strategies. The AI analyzes your business, technical, and organizational constraints to propose a coherent architecture that anticipates future changes. This guide provides optimized prompts to get the most out of Mistral for creating software architectures, from modular monoliths to microservices, as well as event-driven and hexagonal architectures. Each prompt is designed to produce deliverables that can be immediately used by your development team.

0354
💻DeveloppementBeginnerAll AIs

ESLint and Prettier Configuration

Standardize code quality and style as a team

0314
💻DeveloppementAdvancedClaude

Implement Clean Architecture in Practice

Implement Clean Architecture in practice with layers, ports and adapters, use cases, and unit tests without infrastructure.

48646