DEV Community

Cover image for Simplified Guide to JWT Authentication with Spring Boot 🔐
Abhishek Tiwari
Abhishek Tiwari

Posted on

120 2 1 2 2

Simplified Guide to JWT Authentication with Spring Boot 🔐


Securing your applications is paramount in today's digital landscape. One robust approach is JWT (JSON Web Token) authentication. It offers a secure way to verify user identities. In this guide, we will walk through implementing JWT authentication in a Spring Boot app, using a simplified yet effective methodology. We'll cover controllers, services, configurations, and repositories, ensuring you're well-equipped to enhance your app's security.

🚀 Step 1: Setting Up Your Spring Boot Project
Begin by creating a new Spring Boot project or utilizing an existing one. Expedite the process by using Spring Initializr, which sets up essential dependencies like Spring Web, Spring Security, and Spring Data JPA.

<!-- Include necessary dependencies in your pom.xml file -->
    <!-- Spring Web for creating web APIs -->
    <!-- Spring Security for robust authentication and authorization -->
    <!-- Spring Data JPA for streamlined database interactions -->
    <!-- Other dependencies... -->
Enter fullscreen mode Exit fullscreen mode

📦 Step 2: Crafting User Entity and Repository
Design a User class encompassing attributes like id, username, and password. Develop a UserRepository interface to facilitate smooth user data management.

public class User {
    @GeneratedValue(strategy = GenerationType.IDENTITY)
    private Long id;
    private String username;
    private String password;
    // Getters, setters...

public interface UserRepository extends JpaRepository<User, Long> {
    User findByUsername(String username);
Enter fullscreen mode Exit fullscreen mode

🔒 Step 3: Configuring Spring Security
Create a SecurityConfig class extending WebSecurityConfigurerAdapter. Override configure(HttpSecurity http) to establish security rules and manage JWT authentication.

public class SecurityConfig extends WebSecurityConfigurerAdapter {
    private UserDetailsService userDetailsService;

    private JwtUtil jwtUtil;

    protected void configure(HttpSecurity http) throws Exception {
            .addFilter(new JwtAuthenticationFilter(authenticationManager(), jwtUtil))
            .addFilter(new JwtAuthorizationFilter(authenticationManager(), jwtUtil, userDetailsService));

    // Additional configurations...
Enter fullscreen mode Exit fullscreen mode

👤 Step 4: Implementing UserService
Develop a UserService interface with methods to load a user by username and save a new user. Implement UserDetailsService to retrieve user details from the database.

public interface UserService extends UserDetailsService {
    UserDetails loadUserByUsername(String username);
    void saveUser(User user);

public class UserServiceImpl implements UserService {
    private UserRepository userRepository;

    public UserDetails loadUserByUsername(String username) throws UsernameNotFoundException {
        User user = userRepository.findByUsername(username);
        if (user == null) {
            throw new UsernameNotFoundException("User not found: " + username);
        return new
            new ArrayList<>()

    public void saveUser(User user) {;
Enter fullscreen mode Exit fullscreen mode

🔐 Step 5: Generating and Validating JWT Tokens
Create a JwtUtil class to generate and validate JWT tokens.

import io.jsonwebtoken.Claims;
import io.jsonwebtoken.Jwts;
import io.jsonwebtoken.SignatureAlgorithm;
import org.springframework.stereotype.Component;

import java.util.Date;
import java.util.HashMap;
import java.util.Map;
import java.util.function.Function;

public class JwtUtil {
    private final String SECRET = "your-secret-key"; // Replace with a secure secret key
    private final long EXPIRATION_TIME = 900_000; // 15 minutes

    public String extractUsername(String token) {
        return extractClaim(token, Claims::getSubject);

    public Date extractExpiration(String token) {
        return extractClaim(token, Claims::getExpiration);

    public <T> T extractClaim(String token, Function<Claims, T> claimsResolver) {
        final Claims claims = extractAllClaims(token);
        return claimsResolver.apply(claims);

    private Claims extractAllClaims(String token) {
        return Jwts.parser().setSigningKey(SECRET).parseClaimsJws(token).getBody();

    public String generateToken(String username) {
        Map<String, Object> claims = new HashMap<>();
        return createToken(claims, username);

    private String createToken(Map<String, Object> claims, String subject) {
        return Jwts.builder()
                .setIssuedAt(new Date(System.currentTimeMillis()))
                .setExpiration(new Date(System.currentTimeMillis() + EXPIRATION_TIME))
                .signWith(SignatureAlgorithm.HS256, SECRET)

    public boolean isTokenExpired(String token) {
        return extractExpiration(token).before(new Date());

    public boolean validateToken(String token, UserDetails userDetails) {
        final String username = extractUsername(token);
        return (username.equals(userDetails.getUsername()) && !isTokenExpired(token));

    // Additional utility methods...

Enter fullscreen mode Exit fullscreen mode

🔑 Step 6: Authentication Controller
Design an AuthController class to handle user registration and authentication.

public class AuthController {
    private AuthenticationManager authenticationManager;

    private UserService userService;

    private JwtUtil jwtUtil;

    public ResponseEntity<String> registerUser(@RequestBody User user) {
        return ResponseEntity.ok("User registered successfully!");

    public ResponseEntity<String> loginUser(@RequestBody AuthenticationRequest request) {
        try {
                new UsernamePasswordAuthenticationToken(request.getUsername(), request.getPassword())
        } catch (BadCredentialsException e) {
            return ResponseEntity.status(HttpStatus.UNAUTHORIZED).body("Invalid username or password");

        UserDetails userDetails = userService.loadUserByUsername(request.getUsername());
        String token = jwtUtil.generateToken(userDetails);

        return ResponseEntity.ok(token);
Enter fullscreen mode Exit fullscreen mode

🔍 Step 7: Implementing JwtAuthenticationFilter
Create a JwtAuthenticationFilter class to handle JWT authentication and authorization for each request.

public class JwtAuthenticationFilter extends OncePerRequestFilter {
    private UserDetailsService userDetailsService;

    private JwtUtil jwtTokenUtil;

    protected void doFilterInternal(HttpServletRequest request, HttpServletResponse response, FilterChain filterChain)
            throws ServletException, IOException {
        final String authorizationHeader = request.getHeader("Authorization");

        String username = null;
        String jwtToken = null;

        if (authorizationHeader != null && authorizationHeader.startsWith("Bearer ")) {
            jwtToken = authorizationHeader.substring(7);
            try {
                username = jwtTokenUtil.extractUsername(jwtToken);
            } catch (Exception e) {
                // Handle token extraction/validation errors
                System.out.println("Error extracting username from token: " + e.getMessage());

        if (username != null && SecurityContextHolder.getContext().getAuthentication() == null) {
            UserDetails userDetails = userDetailsService.loadUserByUsername(username);

            if (jwtTokenUtil.validateToken(jwtToken, userDetails)) {
                UsernamePasswordAuthenticationToken authenticationToken = new UsernamePasswordAuthenticationToken(
                        userDetails, null, userDetails.getAuthorities());

                authenticationToken.setDetails(new WebAuthenticationDetailsSource().buildDetails(request));


        filterChain.doFilter(request, response);

Enter fullscreen mode Exit fullscreen mode

🌟 Conclusion
You've successfully implemented JWT authentication in your Spring Boot app! 🎉 Your application now boasts heightened security, ensuring only authorized users access sensitive resources. Remember, security is an ongoing journey, so keep yourself informed about best practices and continuously enhance your app's defenses. Happy coding and stay secure! 🔒🔐

Top comments (1)

maximovj profile image
Victor J. Maximo

Is it deprecated or working?