Lesson 70 of 158 – Token Authentication
70%

Token Authentication

Token authentication is a common way to authenticate users after they successfully log in. Instead of sending the user's password with every API request, the application receives a token after login and sends that token with future protected API requests.

Note: Token authentication is especially useful for mobile applications such as React Native apps because the application can use the token for subsequent API requests.

1. What is Token Authentication?

Token authentication is a method where a server provides a token to an authenticated client. The client then uses that token to access protected API resources.

Login
  ↓
Verify User
  ↓
Generate Token
  ↓
Send Token
  ↓
Mobile App
  ↓
Protected API Request
  ↓
Verify Token

2. Why Use Token Authentication?

A mobile application should not send the user's password with every API request. Instead, the application can authenticate once and use a token for later requests.

  • Useful for mobile applications.
  • Reduces repeated password transmission.
  • Allows protected API access.
  • Identifies the authenticated user.
  • Works well with REST APIs.

3. Basic Token Authentication Flow

React Native
     ↓
Email + Password
     ↓
Login API
     ↓
Verify Credentials
     ↓
Generate Token
     ↓
Return Token
     ↓
React Native
     ↓
Store Token
     ↓
Protected API
     ↓
Send Token
     ↓
Verify Token
     ↓
Return Data

4. Login Request

The mobile application first sends the user's login information to the login API.

POST /api/login.php

{
    "email": "user@example.com",
    "password": "123456"
}

The server receives the credentials and verifies the user.

5. Verify User Credentials

The API finds the user in the database and verifies the supplied password against the stored password hash.

$stmt = $pdo->prepare(
    "SELECT * FROM users WHERE email = ?"
);

$stmt->execute([$email]);

$user = $stmt->fetch(PDO::FETCH_ASSOC);

if (
    !$user ||
    !password_verify(
        $password,
        $user['password']
    )
) {
    http_response_code(401);
    exit;
}

6. Generate a Token

After successful authentication, the server generates a token for the authenticated user.

For learning purposes, a token can be represented as a random value.

$token = bin2hex(
    random_bytes(32)
);

echo $token;

The token generation method should be designed according to the authentication system being implemented.

7. Example Token

A token may look like a long random string.

9f3a7d2c8b1e4f6a
0a9c5d7e2b8f1a3c
6d4e9b7c2a5f8d1e

The client does not need to understand the internal meaning of the token. It simply sends the token back to the API when authentication is required.

8. Return Token from Login API

After generating the token, the login API can return it in a JSON response.

echo json_encode([
    "success" => true,
    "message" => "Login successful",
    "token" => $token
]);

9. Token Response Example

{
    "success": true,
    "message": "Login successful",
    "token": "9f3a7d2c8b1e4f6a..."
}

The React Native application reads the token from this response.

10. Store the Token

After receiving the token, the mobile application needs to keep it so that it can use it for later API requests.

Login API
   ↓
Token
   ↓
React Native
   ↓
Token Storage
   ↓
Protected Requests

A later lesson will cover storing authentication tokens in a React Native application.

11. Send Token with API Request

The token can be sent through the Authorization header.

Authorization: Bearer YOUR_TOKEN

The API can then extract and validate the token before returning protected data.

12. Bearer Token

A common token authentication format is the Bearer authentication scheme.

Authorization: Bearer 9f3a7d2c8b1e4f6a...

The word Bearer identifies the authentication scheme and the value after it is the token.

13. Protected API Example

Suppose we have a profile API:

GET /api/profile.php

The API requires a valid token before returning the user's profile.

Request
   ↓
Read Authorization Header
   ↓
Extract Token
   ↓
Validate Token
   ↓
Valid?
 ┌──┴──┐
Yes    No
 ↓      ↓
Data   401

14. Read Token in PHP

The PHP API can read the Authorization header from the incoming request.

$authorization =
    $_SERVER['HTTP_AUTHORIZATION'] ?? '';

if ($authorization === '') {

    http_response_code(401);

    echo json_encode([
        "success" => false,
        "message" => "Token required"
    ]);

    exit;
}

15. Extract Token from Header

$authorization =
    $_SERVER['HTTP_AUTHORIZATION'] ?? '';

if (
    !preg_match(
        '/Bearer\s+(.+)/i',
        $authorization,
        $matches
    )
) {

    http_response_code(401);

    echo json_encode([
        "success" => false,
        "message" =>
            "Invalid authorization header"
    ]);

    exit;
}

$token = trim($matches[1]);

The extracted value can then be checked against the authentication system used by the application.

16. Store Token in Database

One simple token authentication design is to store a token associated with a user in a database table.

For example, a table could contain:

Column Purpose
id Token record ID
user_id Authenticated user
token Authentication token
expires_at Token expiration time
created_at Token creation time

17. Create Token Table

A simple token table can be created using MySQL.

CREATE TABLE user_tokens (
    id INT AUTO_INCREMENT PRIMARY KEY,
    user_id INT NOT NULL,
    token VARCHAR(255) NOT NULL,
    expires_at DATETIME NULL,
    created_at TIMESTAMP DEFAULT CURRENT_TIMESTAMP
);

In a production system, the exact schema should be designed according to the selected authentication strategy and security requirements.

18. Insert Token into Database

$token = bin2hex(
    random_bytes(32)
);

$stmt = $pdo->prepare(
    "INSERT INTO user_tokens
     (user_id, token)
     VALUES (?, ?)"
);

$stmt->execute([
    $user['id'],
    $token
]);

The token is now associated with the authenticated user.

19. Validate Token

A protected API can search for the supplied token.

$stmt = $pdo->prepare(
    "SELECT user_id
     FROM user_tokens
     WHERE token = ?
     LIMIT 1"
);

$stmt->execute([$token]);

$tokenData =
    $stmt->fetch(PDO::FETCH_ASSOC);

if (!$tokenData) {

    http_response_code(401);

    echo json_encode([
        "success" => false,
        "message" => "Invalid token"
    ]);

    exit;
}

20. Get User from Token

After a valid token is found, the API can use the associated user ID to identify the authenticated user.

$userId = $tokenData['user_id'];

$stmt = $pdo->prepare(
    "SELECT id, name, email
     FROM users
     WHERE id = ?"
);

$stmt->execute([$userId]);

$user = $stmt->fetch(
    PDO::FETCH_ASSOC
);

21. Token Expiration

Tokens can have an expiration time. An expired token should not be accepted for protected API requests.

$stmt = $pdo->prepare(
    "SELECT user_id
     FROM user_tokens
     WHERE token = ?
     AND (
         expires_at IS NULL
         OR expires_at > NOW()
     )
     LIMIT 1"
);

$stmt->execute([$token]);

22. Invalid or Expired Token

If the token does not exist or has expired, the API should reject the request.

http_response_code(401);

echo json_encode([
    "success" => false,
    "message" => "Invalid or expired token"
]);

The mobile application can then ask the user to log in again when appropriate.

23. React Native Token Request

const response = await fetch(
    "https://example.com/api/profile.php",
    {
        method: "GET",

        headers: {
            "Authorization":
                "Bearer " + token,
            "Accept": "application/json"
        }
    }
);

const data = await response.json();

console.log(data);

24. Check Authentication Response

The mobile application should check whether the API request was successful.

if (response.ok) {

    console.log("Authenticated");

} else if (response.status === 401) {

    console.log(
        "Authentication required"
    );

}

25. Logout with Token Authentication

A simple logout process can remove or invalidate the token associated with the user.

DELETE FROM user_tokens
WHERE token = ?

After the token is removed, the same token can no longer be used by the protected API.

26. Token Authentication Security

  • Generate tokens using a secure random mechanism.
  • Use HTTPS for authentication requests.
  • Do not put tokens in URLs.
  • Do not log sensitive tokens unnecessarily.
  • Use token expiration when appropriate.
  • Invalidate tokens during logout when required.
  • Protect token storage on the mobile device.
  • Never send passwords with every protected API request.
  • Validate tokens on every protected request.

27. Token Authentication Architecture

                    LOGIN
                      ↓
                React Native
                      ↓
              Email + Password
                      ↓
                PHP Login API
                      ↓
               Verify Password
                      ↓
                Generate Token
                      ↓
                  MySQL
                      ↓
                Return Token
                      ↓
                React Native
                      ↓
               Store Token
                      ↓
              Protected API
                      ↓
             Authorization Header
                      ↓
                Verify Token
                      ↓
                Identify User
                      ↓
                Return JSON

28. Complete PHP Token Example

<?php

header("Content-Type: application/json");

$authorization =
    $_SERVER['HTTP_AUTHORIZATION'] ?? '';

if (
    !preg_match(
        '/Bearer\s+(.+)/i',
        $authorization,
        $matches
    )
) {

    http_response_code(401);

    echo json_encode([
        "success" => false,
        "message" => "Token required"
    ]);

    exit;
}

$token = trim($matches[1]);

$stmt = $pdo->prepare(
    "SELECT user_id
     FROM user_tokens
     WHERE token = ?
     AND (
         expires_at IS NULL
         OR expires_at > NOW()
     )
     LIMIT 1"
);

$stmt->execute([$token]);

$tokenData =
    $stmt->fetch(PDO::FETCH_ASSOC);

if (!$tokenData) {

    http_response_code(401);

    echo json_encode([
        "success" => false,
        "message" => "Invalid or expired token"
    ]);

    exit;
}

echo json_encode([
    "success" => true,
    "message" => "Token is valid",
    "user_id" => $tokenData['user_id']
]);

?>

29. Token Authentication with Postman

Postman can be used to test token-protected APIs.

Step 1: Login using the login API.

POST
http://localhost/api/login.php

Step 2: Copy the returned token.

Step 3: Open the protected API.

GET
http://localhost/api/profile.php

Step 4: Add the Authorization header.

Authorization: Bearer YOUR_TOKEN

If the token is valid, the protected API should return the requested data.

30. Token Authentication Summary

Token authentication allows a user to log in once and then use an authentication token for subsequent protected API requests. The server creates the token after successfully verifying the user's credentials. The mobile application sends the token through the Authorization header, and the server validates it before allowing access.

Login
  ↓
Verify Password
  ↓
Generate Token
  ↓
Return Token
  ↓
React Native
  ↓
Store Token
  ↓
Authorization Header
  ↓
Protected API
  ↓
Validate Token
  ↓
Identify User
  ↓
Return Data

📌 Key Points

  • Token authentication is commonly used to protect REST APIs.
  • The user first authenticates using credentials such as email and password.
  • The server can generate a token after successful authentication.
  • The token can be returned to the React Native application.
  • The mobile application can send the token with protected requests.
  • Bearer tokens are commonly sent through the Authorization header.
  • The API should validate the token before returning protected data.
  • Tokens can be associated with a user in a database.
  • Tokens can have an expiration time.
  • Invalid or expired tokens should be rejected.
  • HTTP 401 is commonly used for missing or invalid authentication.
  • Tokens should not be placed in URLs.
  • HTTPS should be used for authentication communication.
  • Token storage on mobile devices should be handled carefully.
  • The next lesson will introduce JWT authentication.

🧠 Quick Quiz

Question: Where is a Bearer token commonly sent in an HTTP request?