Token Based Auth: Authentication and Authorization
- Date
- 2024-07-10
- Host
- Permit.io
About this event
Authentication is easy to wave away as a solved problem right up until you have to implement it, secure it, and explain the tradeoffs to other people. This meetup is built for that moment: a practical, in-person conversation about token-based auth, how authentication and authorization actually differ, and what teams need to understand to build systems that are both usable and safe. About the Event Token-based authentication sits at the center of modern apps, APIs, and distributed systems, but it often gets discussed in fragments: a JWT here, an access token there, a quick mention of roles and permissions without much context. This event brings those pieces together so attendees can think more clearly about the full picture. The focus is on authentication and authorization as related but distinct concerns. Expect discussion that helps you separate identity from access, understand why tokens are used, and get a better sense of where token-based approaches fit well and where they introduce complexity. Because this is an in-person meetup, the format is well suited to both learning and conversation. It is not just about passively listening; it is also a chance to ask questions, compare approaches, and hear how other people think about implementation choices, security concerns, and real-world constraints. The community and networking angle matters here too. Topics like auth become much easier to understand when you can talk them through with people who have faced similar decisions, whether you are building from scratch, integrating third-party systems, or trying to improve an existing setup. What to Expect You can expect a structured discussion around the fundamentals of token-based auth, followed by room for practical examples, questions, and peer exchange. The goal is to make the topic more concrete, not more abstract. Likely areas of focus include: What token-based authentication means in practical application development The difference between authentication and authorization, and why mixing them up causes design problems Common token concepts such as access, identity, and permission-related flows Tradeoffs and implementation considerations, including usability, maintainability, and risk Open discussion and networking with others interested in security, backend systems, and application architecture Rather than treating auth as a narrow security specialty, this meetup makes space for the broader system design questions around it. How should services verify identity? When should authorization happen? What belongs in a token, and what should stay out of it? These are the kinds of conversations that help people make better technical decisions. You should also expect a social, community-oriented environment. Whether you arrive with deep experience or just enough exposure to know you have questions, the format gives you room to engage at your level and leave with sharper language for discussing auth with teammates, stakeholders, or collaborators. Why Attend If you work on applications, APIs, platforms, or product decisions, token-based auth touches more of your work than you might think. Even when you are not the person writing the core auth logic, you still need to understand the moving parts well enough to design around them, troubleshoot issues, and avoid costly misunderstandings. This event is valuable because it connects conceptual clarity with practical relevance. You will not just hear terminology; you will get a better framework for thinking about identity, access, trust, and how token-based systems behave in real environments. Attendees should come away with: A clearer mental model of how token-based auth works Better language for discussing authentication vs. authorization More confidence evaluating auth-related architecture decisions Insight into common concerns, tradeoffs, and implementation questions New connections with people interested in security, systems, and modern application development There is also real value in hearing how others approach the same problem space. Auth decisions often look simple in diagrams and messy in production. Talking with a room of peers can surface edge cases, assumptions, and lessons that are hard to get from documentation alone. Practical Details This is an in-person event, which makes it a strong fit for anyone who values direct discussion, easier networking, and the ability to ask follow-up questions in a more natural setting. If you have ever found security topics easier to grasp when you can talk them through live, this format will work in your favor. The meetup takes place on Wednesday, July 10 at 6:00 PM GMT+2. That timing makes it well suited to an after-work community gathering, with space to learn, connect, and discuss without the rushed feel of a short online session. Since the event is tagged across community, networking, meetup, social, and other, you can expect a balanced atmosphere: serious enough to reward technical curiosity, but approachable enough for conversation and relationship-building. Come ready to listen, ask questions, share your perspective, and meet people who care about building systems thoughtfully. If token-based auth is already part of your day-to-day work, this is a chance to refine your thinking. If it is an area you need to get better at, this is a strong place to build that understanding in the company of others who are working through similar questions.
Who should attend
This is for you if you want a clearer, more practical understanding of how token-based authentication and authorization work in real systems. - You build or maintain **web apps, mobile apps, or APIs** and want to better understand the auth layer those systems depend on. - You are a **backend engineer, full-stack developer, or platform-minded builder** who needs clearer mental models for tokens, identity, and permissions. - You work on **security-sensitive product decisions** and want to speak more confidently about authentication vs. authorization when planning features or reviewing architecture. - You have used auth libraries or third-party identity tools before, but want to understand **what is happening under the hood** and what tradeoffs come with different approaches. - You enjoy **technical meetups with a community feel**, where learning is paired with conversation, questions, and networking. - You are early in your journey with auth and want an **approachable in-person setting** to ask questions, hear how others think, and leave with concepts that actually stick. If you have ever felt that auth is important, confusing, and too often explained in scattered pieces, this meetup is designed to bring those pieces together.