JWT Authentication Backend Developer
Budget / Salary$10–30
TypeFreelance project
LocationRemote
Posted2 hours ago
I’m looking for help adding a solid, production-ready JSON Web Token (JWT) authentication layer to an existing backend and then packaging everything so it can be deployed smoothly through modern DevOps practices.
Here is what I need:
• A login and token-issuing endpoint that returns signed JWTs (access + refresh)
• Middleware or guards that validate and refresh tokens on every protected route
• Role/permission claims embedded in the token and enforced server-side
• Secure password hashing and basic user management endpoints
• Container-ready code (Docker) plus an automated CI/CD pipeline so new commits roll out with zero downtime (GitHub Actions or similar)
• Environment-based configuration for secrets, keys, and database connections
• Clear, concise documentation so another engineer can pick it up quickly
I’m currently agnostic about the underlying database—feel free to recommend MySQL, MongoDB, PostgreSQL, or another store if it fits the design cleanly. Likewise, the core language or framework is flexible as long as the JWT flow is standards-compliant and the deployment story stays straightforward.
Please ensure that:
1. Tokens are signed with a rotating secret or asymmetric key.
2. Refresh token reuse is detected and blocked.
3. All sensitive values are supplied only through environment variables.
If you’ve built stateless auth systems before and are comfortable wiring up Dockerized services to automated pipelines, I’d love to see your approach and a short timeline.
Here is what I need:
• A login and token-issuing endpoint that returns signed JWTs (access + refresh)
• Middleware or guards that validate and refresh tokens on every protected route
• Role/permission claims embedded in the token and enforced server-side
• Secure password hashing and basic user management endpoints
• Container-ready code (Docker) plus an automated CI/CD pipeline so new commits roll out with zero downtime (GitHub Actions or similar)
• Environment-based configuration for secrets, keys, and database connections
• Clear, concise documentation so another engineer can pick it up quickly
I’m currently agnostic about the underlying database—feel free to recommend MySQL, MongoDB, PostgreSQL, or another store if it fits the design cleanly. Likewise, the core language or framework is flexible as long as the JWT flow is standards-compliant and the deployment story stays straightforward.
Please ensure that:
1. Tokens are signed with a rotating secret or asymmetric key.
2. Refresh token reuse is detected and blocked.
3. All sensitive values are supplied only through environment variables.
If you’ve built stateless auth systems before and are comfortable wiring up Dockerized services to automated pipelines, I’d love to see your approach and a short timeline.
Apply on Freelancer →
Project sourced from Freelancer.com. Applications happen directly on the original platform — we never collect your data.