What is the difference between JWT and session cookies?
PICTURE THIS: A SENTENCE BECOMES TOKENS
The model does not read letters like humans. It reads these pieces, then predicts the next one.
Simple meaning
Sessions store server-side state and send a session id cookie.
WHY — Auth instead of guessing?
Why interviewers care about Auth:
contrast on Auth, not two memorised paragraphs.
the developer, then one case where picking wrong hurts.
Name the idea, why it exists, then one short example.
End with when you use it and one common pitfall.
STEPS — What happens with tokens?
Before the model can read a sentence, it goes through these steps:
- 1Sessions store server-side state
and send a session id cookie.
- 2JWT is a signed
token the client stores and sends back.
- 3JWT scales without sticky
sessions but needs careful expiry and revocation design.
- 4Context mix
Attention looks at nearby tokens together.
- 5Next token
The model scores what should come next.
- 6Decode
IDs turn back into readable text.
EXAMPLE — See it in action
Let's see how a real sentence is tokenized (tokens may vary by model):
Note: Actual tokens and IDs depend on the tokenizer (e.g., GPT, Llama, etc.).
Key takeaway
Sessions store server-side state and send a session id cookie. JWT is a signed token the client stores and sends back.