How do you authenticate a WebSocket connection in MERN?
PICTURE THIS: A SENTENCE BECOMES TOKENS
The model does not read letters like humans. It reads these pieces, then predicts the next one.
Simple meaning
Send the access token in the handshake auth payload or a cookie and verify it before joining rooms.
WHY — WebSockets instead of guessing?
Why interviewers care about WebSockets:
question about WebSockets.
trade-offs, and what you would actually do on a Full Stack project - not buzzwords.
Name the idea, why it exists, then one short example.
End with when you use it and one common pitfall.
STEPS — What happens with tokens?
Before the model can read a sentence, it goes through these steps:
- 1Send the access token
in the handshake auth payload or a cookie and verify it before joining rooms.
- 2Reject the socket if
the token is missing or expired.
- 3Authorize again on privileged
events so a connected socket cannot act as another user.
- 4Context mix
Attention looks at nearby tokens together.
- 5Next token
The model scores what should come next.
- 6Decode
IDs turn back into readable text.
EXAMPLE — See it in action
Let's see how a real sentence is tokenized (tokens may vary by model):
Note: Actual tokens and IDs depend on the tokenizer (e.g., GPT, Llama, etc.).
Key takeaway
Send the access token in the handshake auth payload or a cookie and verify it before joining rooms. Reject the socket if the token is missing or expired.