How to use JWT (JSON Web Tokens) with Django and Python for creating the REST API for signup and login
I've being trying to implement the JWT (JSON Web Tokens) in the Django project. But I was not able to achieve the same. Can you please help me with some tutorial or tips or links to study the same.
I tried using the pyjwt in my project, but the token generated every time I hit the API was same for the same user email address and password.
django python-3.x django-rest-framework jwt pyjwt
add a comment |
I've being trying to implement the JWT (JSON Web Tokens) in the Django project. But I was not able to achieve the same. Can you please help me with some tutorial or tips or links to study the same.
I tried using the pyjwt in my project, but the token generated every time I hit the API was same for the same user email address and password.
django python-3.x django-rest-framework jwt pyjwt
1
You'll need to provide some code, showing what you've tried and information about exactly what problem you're experiencing.
– Toby
Dec 28 '18 at 0:39
add a comment |
I've being trying to implement the JWT (JSON Web Tokens) in the Django project. But I was not able to achieve the same. Can you please help me with some tutorial or tips or links to study the same.
I tried using the pyjwt in my project, but the token generated every time I hit the API was same for the same user email address and password.
django python-3.x django-rest-framework jwt pyjwt
I've being trying to implement the JWT (JSON Web Tokens) in the Django project. But I was not able to achieve the same. Can you please help me with some tutorial or tips or links to study the same.
I tried using the pyjwt in my project, but the token generated every time I hit the API was same for the same user email address and password.
django python-3.x django-rest-framework jwt pyjwt
django python-3.x django-rest-framework jwt pyjwt
asked Dec 28 '18 at 0:22
Ramanpreet Singh
134
134
1
You'll need to provide some code, showing what you've tried and information about exactly what problem you're experiencing.
– Toby
Dec 28 '18 at 0:39
add a comment |
1
You'll need to provide some code, showing what you've tried and information about exactly what problem you're experiencing.
– Toby
Dec 28 '18 at 0:39
1
1
You'll need to provide some code, showing what you've tried and information about exactly what problem you're experiencing.
– Toby
Dec 28 '18 at 0:39
You'll need to provide some code, showing what you've tried and information about exactly what problem you're experiencing.
– Toby
Dec 28 '18 at 0:39
add a comment |
1 Answer
1
active
oldest
votes
JWT are combinations of three parts: Header, Payload and Verify Signature (see the image bellow), they can carry information about the user (name, id, etc.) or even the expiration time of the token. So, if none of this information changes, the token will be the same.
Every time a user logs on the system, a token will be generated using their informations (username, id, email, etc). If theese information not change, token not change. Unless the expiration time is added to the token, so, every time that an user logs, a new expiration time will be generated and added to the token, creating a new one. When the token expires, client can request a new access token (refresh)
Links
JWT: Official website- Stateless Authentication using JWT
- Refresh Tokens
Django REST framework JWT: Another package to support JWT Authentication for Django REST framework
1
Thank you for this really helpful answer. (y)
– Ramanpreet Singh
Dec 28 '18 at 18:56
add a comment |
Your Answer
StackExchange.ifUsing("editor", function () {
StackExchange.using("externalEditor", function () {
StackExchange.using("snippets", function () {
StackExchange.snippets.init();
});
});
}, "code-snippets");
StackExchange.ready(function() {
var channelOptions = {
tags: "".split(" "),
id: "1"
};
initTagRenderer("".split(" "), "".split(" "), channelOptions);
StackExchange.using("externalEditor", function() {
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled) {
StackExchange.using("snippets", function() {
createEditor();
});
}
else {
createEditor();
}
});
function createEditor() {
StackExchange.prepareEditor({
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: true,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: 10,
bindNavPrevention: true,
postfix: "",
imageUploader: {
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
},
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
});
}
});
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f53952327%2fhow-to-use-jwt-json-web-tokens-with-django-and-python-for-creating-the-rest-ap%23new-answer', 'question_page');
}
);
Post as a guest
Required, but never shown
1 Answer
1
active
oldest
votes
1 Answer
1
active
oldest
votes
active
oldest
votes
active
oldest
votes
JWT are combinations of three parts: Header, Payload and Verify Signature (see the image bellow), they can carry information about the user (name, id, etc.) or even the expiration time of the token. So, if none of this information changes, the token will be the same.
Every time a user logs on the system, a token will be generated using their informations (username, id, email, etc). If theese information not change, token not change. Unless the expiration time is added to the token, so, every time that an user logs, a new expiration time will be generated and added to the token, creating a new one. When the token expires, client can request a new access token (refresh)
Links
JWT: Official website- Stateless Authentication using JWT
- Refresh Tokens
Django REST framework JWT: Another package to support JWT Authentication for Django REST framework
1
Thank you for this really helpful answer. (y)
– Ramanpreet Singh
Dec 28 '18 at 18:56
add a comment |
JWT are combinations of three parts: Header, Payload and Verify Signature (see the image bellow), they can carry information about the user (name, id, etc.) or even the expiration time of the token. So, if none of this information changes, the token will be the same.
Every time a user logs on the system, a token will be generated using their informations (username, id, email, etc). If theese information not change, token not change. Unless the expiration time is added to the token, so, every time that an user logs, a new expiration time will be generated and added to the token, creating a new one. When the token expires, client can request a new access token (refresh)
Links
JWT: Official website- Stateless Authentication using JWT
- Refresh Tokens
Django REST framework JWT: Another package to support JWT Authentication for Django REST framework
1
Thank you for this really helpful answer. (y)
– Ramanpreet Singh
Dec 28 '18 at 18:56
add a comment |
JWT are combinations of three parts: Header, Payload and Verify Signature (see the image bellow), they can carry information about the user (name, id, etc.) or even the expiration time of the token. So, if none of this information changes, the token will be the same.
Every time a user logs on the system, a token will be generated using their informations (username, id, email, etc). If theese information not change, token not change. Unless the expiration time is added to the token, so, every time that an user logs, a new expiration time will be generated and added to the token, creating a new one. When the token expires, client can request a new access token (refresh)
Links
JWT: Official website- Stateless Authentication using JWT
- Refresh Tokens
Django REST framework JWT: Another package to support JWT Authentication for Django REST framework
JWT are combinations of three parts: Header, Payload and Verify Signature (see the image bellow), they can carry information about the user (name, id, etc.) or even the expiration time of the token. So, if none of this information changes, the token will be the same.
Every time a user logs on the system, a token will be generated using their informations (username, id, email, etc). If theese information not change, token not change. Unless the expiration time is added to the token, so, every time that an user logs, a new expiration time will be generated and added to the token, creating a new one. When the token expires, client can request a new access token (refresh)
Links
JWT: Official website- Stateless Authentication using JWT
- Refresh Tokens
Django REST framework JWT: Another package to support JWT Authentication for Django REST framework
edited Dec 28 '18 at 3:52
answered Dec 28 '18 at 3:47
Lucas Weyne
250111
250111
1
Thank you for this really helpful answer. (y)
– Ramanpreet Singh
Dec 28 '18 at 18:56
add a comment |
1
Thank you for this really helpful answer. (y)
– Ramanpreet Singh
Dec 28 '18 at 18:56
1
1
Thank you for this really helpful answer. (y)
– Ramanpreet Singh
Dec 28 '18 at 18:56
Thank you for this really helpful answer. (y)
– Ramanpreet Singh
Dec 28 '18 at 18:56
add a comment |
Thanks for contributing an answer to Stack Overflow!
- Please be sure to answer the question. Provide details and share your research!
But avoid …
- Asking for help, clarification, or responding to other answers.
- Making statements based on opinion; back them up with references or personal experience.
To learn more, see our tips on writing great answers.
Some of your past answers have not been well-received, and you're in danger of being blocked from answering.
Please pay close attention to the following guidance:
- Please be sure to answer the question. Provide details and share your research!
But avoid …
- Asking for help, clarification, or responding to other answers.
- Making statements based on opinion; back them up with references or personal experience.
To learn more, see our tips on writing great answers.
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f53952327%2fhow-to-use-jwt-json-web-tokens-with-django-and-python-for-creating-the-rest-ap%23new-answer', 'question_page');
}
);
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
1
You'll need to provide some code, showing what you've tried and information about exactly what problem you're experiencing.
– Toby
Dec 28 '18 at 0:39