JWT is a signed token with user claims. Prefer HttpOnly secure cookies for browsers (harder for XSS to steal). LocalStorage is simpler but riskier if XSS exists. ShopNest API validates Bearer tokens on every protected call.
Oracle rounds often probe: SQL depth.
Themes commonly reported in public MNC interview experiences (AmbitionBox / LinkedIn / Glassdoor-style). Practice aloud; keep answers this short in the real round.