Where should a browser store an auth token?
PICTURE THIS: A SENTENCE BECOMES TOKENS
The model does not read letters like humans. It reads these pieces, then predicts the next one.
Simple meaning
HTTP-only cookies are harder for stolen scripts to read because JavaScript cannot access them.
WHY — Auth instead of guessing?
Why interviewers care about Auth:
who only read docs from people who shipped.
and tied to Full Stack work.
Name the idea, why it exists, then one short example.
End with when you use it and one common pitfall.
STEPS — What happens with tokens?
Before the model can read a sentence, it goes through these steps:
- 1HTTP-only cookies are harder
for stolen scripts to read because JavaScript cannot access them.
- 2localStorage is simple but
any XSS can steal the token.
- 3Interviewers want you to
name that trade-off rather than claim one place is always correct.
- 4Context mix
Attention looks at nearby tokens together.
- 5Next token
The model scores what should come next.
- 6Decode
IDs turn back into readable text.
EXAMPLE — See it in action
Let's see how a real sentence is tokenized (tokens may vary by model):
Note: Actual tokens and IDs depend on the tokenizer (e.g., GPT, Llama, etc.).
Key takeaway
HTTP-only cookies are harder for stolen scripts to read because JavaScript cannot access them. localStorage is simple but any XSS can steal the token.