Why should you not store JWTs in localStorage?
PICTURE THIS: A SENTENCE BECOMES TOKENS
The model does not read letters like humans. It reads these pieces, then predicts the next one.
Simple meaning
Any XSS on the origin can read localStorage and send the token to an attacker.
WHY — Security instead of guessing?
Why interviewers care about Security:
on Security.
the situation, the default choice, and one exception - that reads as experience.
Name the idea, why it exists, then one short example.
End with when you use it and one common pitfall.
STEPS — What happens with tokens?
Before the model can read a sentence, it goes through these steps:
- 1Any XSS on the
origin can read localStorage and send the token to an attacker.
- 2HttpOnly cookies are not
readable by scripts.
- 3If a team still
uses localStorage I talk about short expiry, CSP, and treating XSS as a full account compromise.
- 4Context mix
Attention looks at nearby tokens together.
- 5Next token
The model scores what should come next.
- 6Decode
IDs turn back into readable text.
EXAMPLE — See it in action
Here's a short line you can speak, broken into clear beats:
Note: Adapt this scaffold to your own project — keep it under 60–90 seconds.
Key takeaway
Any XSS on the origin can read localStorage and send the token to an attacker. HttpOnly cookies are not readable by scripts.