Dev Docs
⌘K
    github
    ⌘K
      • Design Patterns
        • Creational Patterns
          • Singleton Pattern
        • Structural Patterns
          • Adapter Pattern
          • Composite Pattern
          • Decorator Pattern
          • Facade Pattern
          • Proxy Pattern
        • Behavioral Patterns
          • Observer Pattern
          • Chain Of Responsibility
          • Command
          • Iterator
          • Mediator
          • Memento
          • State
          • Strategy
          • Template
          • Visitor
      • System Design Concepts
        • CAP Theorem
        • Capacity Estimation
        • Database Replication
          • Leader-Based Replication
          • Consistency Models
          • Read Replicas & Replication Lag
          • Replication Implementations
        • Database Clustering
        • Multi Leader Replication
        • Distributed Systems
          • CAP Theorem
          • PACELC
          • Consistency Models
          • Idempotency & Exactly-Once Semantics
          • Distributed Locking
          • Leader Election
          • Gossip Protocol
          • Quorum Reads & Writes
          • Saga Pattern
          • Outbox Pattern
          • Logical Clocks
          • Multi-Region Design & Geo-Replication
        • Consensus & Coordination
          • Two-Phase Commit (2PC)
          • Raft Consensus
        • Messaging & Event-Driven
          • Message Queues vs Event Streams
          • Kafka Deep Dive
          • Event-Driven Architecture
          • CQRS: Command Query Responsibility Segregation
          • Dead Letter Queues & Retry Strategies
        • Rate Limiting
          • Rate Limiting Algorithms
        • Reliability Patterns
          • Circuit Breaker Pattern
          • Bulkhead Pattern
          • Back-Pressure & Load Shedding
        • API Design
          • API Pagination
          • API Idempotency Keys & Versioning
        • Architecture
          • Microservices vs Monolith
          • Service Discovery & API Gateway
        • Networking
          • TCP vs UDP
          • DNS
          • HTTP/1.1
          • HTTP/2
          • HTTP/3 and QUIC
          • HTTP Evolution
          • HTTP Headers
          • HTTP Status Codes
          • Reverse Proxy vs Forward Proxy
          • Load Balancing
          • CDN
          • WebSockets vs Long Polling vs SSE
          • REST vs gRPC vs GraphQL
        • Search, Geospatial & Real-Time
          • Search Autocomplete / Typeahead
          • GeoHash
          • QuadTree
          • Uber-Style Location Indexing
          • Presence & Online Status
          • Notification Fanout Strategies
          • WebSocket at Scale
          • MQTT
          • Payment System Design
          • Distributed Job Scheduling
          • Unique ID Generation
        • Storage & Databases
          • Database Indexes
          • B+ Tree
          • Hash Index
          • LSM Trees
          • RDBMS Internals
          • SQL vs NoSQL Decision Framework
          • Key-Value Stores (Redis)
          • Wide-Column Stores (Cassandra)
          • Document Stores (MongoDB)
          • Object Storage (S3)
          • Time-Series Databases
          • Columnar Storage
          • Consistent Hashing
          • Bloom Filters & HyperLogLog
          • Caching Patterns
          • Cache Eviction
          • Hot-Key / Hotspot Problems
          • Full-Text Search
        • Scaling
          • Database Sharding
        • Security
          • JWT (JSON Web Tokens)
            • JWT Structure
            • Signing Algorithms: HS256 vs RS256
            • Stateless Validation
            • Security Pitfalls
            • Tokens in Practice
          • OAuth 2.0 & OIDC
            • Grant Types
            • Token Lifecycle
            • OIDC: Identity Layer
            • Token Revocation
            • Architecture & Practice
          • API Authentication Patterns
            • API Keys
            • HMAC Signing
            • mTLS (Mutual TLS)
            • JWT Bearer Tokens
            • Choosing the Right Scheme
        • Data Engineering
          • Batch vs Streaming
          • Stream Processing Engines
          • Data Warehouse Basics
          • Change Data Capture (CDC)
        • AI / ML Systems
          • Recommendation System Design
          • Feature Store Design
          • ML Platform Design
      • System Design Use Cases
        • Distributed Cache
          • High-Level Design
          • Deep Dive
          • Wrap-Up
        • Distributed Key-Value Store
          • High-Level Design
          • Storage Engine Deep Dive
          • Replication and Consistency Deep Dive
          • Wrap-Up
        • Distributed Message Queue
          • High-Level Design
          • Deep Dive
          • Wrap-Up
        • Dropbox / Google Drive
          • High-Level Design
          • Chunking, Dedup & Delta-Sync Deep Dive
          • Sync Engine & Access Control Deep Dive
          • Wrap-Up
        • Google Maps / Navigation
          • High-Level Design
          • Deep Dive — Routing
          • Deep Dive — Tiles & Traffic
          • Wrap-Up
        • Instagram / Photo Sharing
          • High-Level Design
          • Feed Deep Dive
          • Media Deep Dive
          • Wrap-Up
        • Leaderboard
          • High-Level Design
          • Deep Dive
          • Wrap-Up
        • Notification System
          • High-Level Design
          • Deep Dive
          • Wrap-Up
        • Payment System
          • High-Level Design
          • Ledger Deep Dive
          • Reliability Deep Dive
          • Wrap-Up
        • Rate Limiter Service
          • High-Level Design
          • Deep Dive
          • Wrap-Up
        • Search Engine
          • High-Level Design
          • Indexing Deep Dive
          • Ranking Deep Dive
          • Wrap-Up
        • Twitter Feed / Home Timeline
          • High-Level Design
          • Fan-Out Deep Dive
          • Ranking, Media and Mutations Deep Dive
          • Wrap-Up
        • Typeahead / Autocomplete
          • High-Level Design
          • Deep Dive
          • Wrap-Up
        • Uber / Ride-Sharing
          • High-Level Design
          • Location Service Deep Dive
          • Matching, Surge, Tracking & Payment Deep Dive
          • Wrap-Up
        • URL Shortener
          • High-Level Design
          • Deep Dive
          • Wrap-Up
        • Web Crawler
          • High-Level Design
          • Frontier and Deduplication Deep Dive
          • Politeness and Trap Avoidance Deep Dive
          • Scale and Coordination Deep Dive
          • Wrap-Up
        • WhatsApp / Chat System
          • High-Level Design
          • Delivery Deep Dive
          • Encryption Deep Dive
          • Wrap-Up
        • YouTube / Video Streaming
          • High-Level Design
          • Transcoding Deep Dive
          • Streaming Deep Dive
          • Wrap-Up
      • Graph Theory
        • Dijkstra's Algorithm
        • Problems
          • Cycle in Directed Graphs
        • Search
          • Breadth First Search
          • Depth First Search
        • Topological Sorting
        • Travelling Salesman Problem
      • Low-Level-Designs
        • Logger Framework
        • Blocking Queue
        • Distributed Unique ID Generator
        • Meeting Scheduler
        • Search Framework
      • Machine-Learnings
        • _index
          • gradient-descent
      • CAP Theorem
      • Capacity Estimation
      • Database Replication
        • Leader-Based Replication
        • Consistency Models
        • Read Replicas & Replication Lag
        • Replication Implementations
      • Database Clustering
      • Multi Leader Replication
      • Distributed Systems
        • CAP Theorem
        • PACELC
        • Consistency Models
        • Idempotency & Exactly-Once Semantics
        • Distributed Locking
        • Leader Election
        • Gossip Protocol
        • Quorum Reads & Writes
        • Saga Pattern
        • Outbox Pattern
        • Logical Clocks
        • Multi-Region Design & Geo-Replication
      • Consensus & Coordination
        • Two-Phase Commit (2PC)
        • Raft Consensus
      • Messaging & Event-Driven
        • Message Queues vs Event Streams
        • Kafka Deep Dive
        • Event-Driven Architecture
        • CQRS: Command Query Responsibility Segregation
        • Dead Letter Queues & Retry Strategies
      • Rate Limiting
        • Rate Limiting Algorithms
      • Reliability Patterns
        • Circuit Breaker Pattern
        • Bulkhead Pattern
        • Back-Pressure & Load Shedding
      • API Design
        • API Pagination
        • API Idempotency Keys & Versioning
      • Architecture
        • Microservices vs Monolith
        • Service Discovery & API Gateway
      • Networking
        • TCP vs UDP
        • DNS
        • HTTP/1.1
        • HTTP/2
        • HTTP/3 and QUIC
        • HTTP Evolution
        • HTTP Headers
        • HTTP Status Codes
        • Reverse Proxy vs Forward Proxy
        • Load Balancing
        • CDN
        • WebSockets vs Long Polling vs SSE
        • REST vs gRPC vs GraphQL
      • Search, Geospatial & Real-Time
        • Search Autocomplete / Typeahead
        • GeoHash
        • QuadTree
        • Uber-Style Location Indexing
        • Presence & Online Status
        • Notification Fanout Strategies
        • WebSocket at Scale
        • MQTT
        • Payment System Design
        • Distributed Job Scheduling
        • Unique ID Generation
      • Storage & Databases
        • Database Indexes
        • B+ Tree
        • Hash Index
        • LSM Trees
        • RDBMS Internals
        • SQL vs NoSQL Decision Framework
        • Key-Value Stores (Redis)
        • Wide-Column Stores (Cassandra)
        • Document Stores (MongoDB)
        • Object Storage (S3)
        • Time-Series Databases
        • Columnar Storage
        • Consistent Hashing
        • Bloom Filters & HyperLogLog
        • Caching Patterns
        • Cache Eviction
        • Hot-Key / Hotspot Problems
        • Full-Text Search
      • Scaling
        • Database Sharding
      • Security
        • JWT (JSON Web Tokens)
          • JWT Structure
          • Signing Algorithms: HS256 vs RS256
          • Stateless Validation
          • Security Pitfalls
          • Tokens in Practice
        • OAuth 2.0 & OIDC
          • Grant Types
          • Token Lifecycle
          • OIDC: Identity Layer
          • Token Revocation
          • Architecture & Practice
        • API Authentication Patterns
          • API Keys
          • HMAC Signing
          • mTLS (Mutual TLS)
          • JWT Bearer Tokens
          • Choosing the Right Scheme
      • Data Engineering
        • Batch vs Streaming
        • Stream Processing Engines
        • Data Warehouse Basics
        • Change Data Capture (CDC)
      • AI / ML Systems
        • Recommendation System Design
        • Feature Store Design
        • ML Platform Design
      System Design Concepts
      Security

      Security

      JWT (JSON Web Tokens)
      Header.payload.signature structure, HS256 vs RS256 key models, stateless validation, JWKS key distribution, and alg:none / key-confusion attacks
      OAuth 2.0 & OIDC
      Authorization code flow, PKCE for public clients, access/refresh token lifecycle, OIDC identity layer, and token revocation strategies
      API Authentication Patterns
      API keys (hashed storage), HMAC request signing (replay prevention), mTLS for microservices, JWT Bearer tokens, and scheme selection by caller trust level