How do you handle authentication in a REST API? Typical options include: ● JWT tokens ● OAuth ● API keys ● Sessions (less common for APIs) 📌 Usually, the client includes a token in the Authorization header:
Answer: uthorization: Bearer <token> The server verifies the token on every request.
What interviewers expect
- A clear definition tied to Node.js in Node.js projects
- Trade-offs (performance, maintainability, security, cost)
- When you would and would not use it in production
Real-world example
In a production Node.js application, teams apply this when handling user-facing features or integration boundaries. For example, you might use it during a sprint where reliability and observability matter—logging metrics, validating edge cases, and documenting the decision in an ADR so future developers understand why the approach was chosen.
How to explain in the interview
- Define the concept in one or two sentences.
- Context — where it fits in Node.js architecture.
- Example — a specific project, bug, or performance win.
- Trade-off — what you gain vs what you sacrifice.
Tip: Practice aloud on Toolliyo mock interview or the Interview Q&A section before your real interview.