Interview questions

Security & Auth interview questions

Authentication, authorization and secure storage.

Security & Auth

How does OAuth 2.0 work?

OAuth 2.0 lets an application get limited access to a user’s resources without handling their password. The user signs in with an authorization server and approves scopes; the app receives an authorization code, exchanges it for an access token and calls the resource server with that token. For public clients, the code flow is protected with PKCE.

Security & Auth

What is a JWT and what are its security pitfalls?

A JSON Web Token is a compact, signed token with three base64url parts: header, payload (claims) and signature. Servers verify the signature to trust the claims without a database lookup. JWTs are signed, not encrypted, so never put secrets in them; keep them short-lived, validate algorithm, issuer, audience and expiry, and plan for revocation.

Security & Auth

What is the difference between authentication and authorization?

Authentication verifies who you are — with a password, passkey, one-time code or single sign-on. Authorization decides what you are allowed to do once identified — through roles, permissions, attributes or policies. Authentication happens first; authorization is checked on every protected action, ideally on the server and close to the data.

Security & Auth

How should passwords be stored?

Never store passwords in plain text or with fast hashes such as SHA-256 alone. Use a slow, salted password hashing function designed for the purpose — Argon2id, scrypt or bcrypt — with a unique salt per password and a work factor tuned to your hardware. Compare hashes in constant time and rehash when you raise the cost.

Walk into your next interview prepared

Start free, install the Windows app and run a practice session today.

Security & Auth Interview Questions & Answers | Ask Agents