Home/Labs/Session vs JWT Ledger
All 280 Labs
INTERACTIVE LAB🍪

Session vs Token Authentication Cost Lab (Interactive)

Weigh Redis RAM and lookup latency against token revocation exposure windows. A live cost model of server-side sessions, stateless JWTs, and the refresh-token hybrid under varying concurrency, token TTLs, and credential-theft incidents.

Sessions vs JWT vs Hybrid

Size the Redis state, per-request latency, and revocation window of each model, then trigger a token-theft incident.

Redis RAM (raw sessions)

9.5 GB

With replicas + overhead

33.4 GB

Stateful lookups / sec

50,000

Verify latency / req

0.05 ms

Token payload

527 B

Refresh-token state

1.9 GB

Idle state. The core dilemma is revocability vs scalability: sessions keep state server-side so logout is a simple key delete; JWTs push state into a signed payload so any microservice verifies locally in ~0.05 ms, at the cost of a revocation window equal to the token's TTL. Toggle the incident to see the difference.

How It Works Under the Hood

Server-side sessions store one record per login: every request pays a stateful cache lookup and the cluster pays RAM for the entire population, but revocation is instant. Stateless JWTs move verification to asymmetric or HMAC signature checks, eliminating lookups but orphaning the revocation problem, because a stolen token lives until its TTL expires. The refresh-token hybrid restores control: fifteen-minute access tokens plus rotating refresh tokens that are themselves server-checked, yielding near-instant kill switches at the cost of one lookup per refresh. The simulator prices RAM, lookups per second, and exposure windows for each mode.

Core Architectural Principles

  • Session RAM scales with 1 KB per active session times replication factor, independent of request rate.
  • JWT verify is pure CPU (~0.1-0.5 ms), so auth cost tracks requests per second instead of population.
  • Theft mode exposes the full TTL as an unanswered revocation window until rotation checkpoints run.
Interview Round Script

Frame it as revocation versus state: sessions give instant logout but a Redis lookup per request and a shared cache dependency; JWTs scale verification to any node but cannot be revoked before expiry. Then propose the hybrid, short-lived access tokens with rotating refresh tokens kept in httpOnly cookies, and say out loud which system you chose to make stateful and why.

Key Trade-Offs

Stateful sessions buy instant revocation at the price of a hot cache dependency; stateless tokens buy scale at the price of exposure windows.

Related Curriculum Chapter

Session-Based vs Token-Based (JWT) Authentication

Read Full Chapter Blueprint

Explore More Interactive Labs

View All 280 Labs