Ankit Kumar Tiwari, Hardik Srivastava, Vaibhav Baishkhiyar, Shikhar Gupta | International Journal of Electrical Power System and Technology | Vol 12, Issue 02
Abstract
More than 80% of web application breaches are rooted in credential compromise, yet password-based login continues to be the default choice in most MERN stack deployments. This paper reports on a side-by-side implementation of JSON Web Token (JWT) and Web Authentication (WebAuthn) within a shared MERN reference application built on React 18, Express.js 4.18, Node.js v20 LTS, and MongoDB Atlas M10. The JWT branch uses bcrypt at cost factor 12 with RS256 signing; the WebAuthn branch is built around @simplewebauthn v9.0. We subjected both to five attack simulations—XSS token extraction, phishing redirection, replay capture, credential-store breach, and concurrent session hijacking—and profiled 1,000 sequential authentication events per mechanism using Node.js perf_hooks. The outcome is not a single winner. WebAuthn defeats phishing and replay at the protocol level; a MongoDB breach leaks nothing reusable—only COSE-encoded public keys that are meaningless without the hardware-resident private key. JWT answers with 1.2 ms hot-path stateless verification, zero database calls per protected request, and a development timeline roughly three times shorter. For startups and consumer-facing products, a well-configured JWT implementation remains the rational default. For regulated industries, WebAuthn’s hardware- bound guarantees are becoming non-negotiable. We close by formalising a hybrid design—WebAuthn for the initial binding event, short-lived RS256 JWT for session propagation—as the architecture best suited to teams that refuse to treat security and scalability as opposing forces.
Keywordss - JWT, WebAuthn, FIDO2, MERN Stack, Passwordless Authentication, bcrypt, Node.js, MongoDB, Web Security, Passkeys
đź”’ This is a subscription article
Full text is available to subscribers and institutional members. Please choose an option below to access it.
SubscribePurchase this articleInstitutional / Login accessReferences
- Chowdhury MS. Best Practices for Securing MERN Stack Applications: A Comprehensive Study of Authentication, Authorization and Data Protection.
- Sheffer Y, Hardt D, Jones M. JSON web token best current practices. RFC 8725. 2020 Feb.
- Balfanz D, Czeskis A, Hodges J, Jones JC, Jones MB, Kumar A, Liao A, Lindemann R, Lundberg E. Web Authentication: An API for accessing Public Key Credentials Level 1. March 2019. REC. URL: https://www. w3. org/TR/webauthn-1. 2021.
- Alliance FI. FIDO2: Web Authentication (WebAuthn). URL: https://fidoalliance. org/fido2/fido2- webauthentication-webauthn. 2023 Oct.
- Urban P. Zabezpečenà distribuovaných cloudových systémů.
- Grassi PA, Perlner R, Newton EM, Regenscheid A, Burr WE, Richer JP, Lefkovitz N, Danker JM, Theofanos M. Digital identity guidelines: Authentication and lifecycle management [including updates as of 12-01-2017].
- Provos N, Mazieres D. A future-adaptable password scheme. InUSENIX ATC, FREENIX Track 1999 Jun 6 (pp. 81-91).
- AlQahtani AA, Almuairfi S, Hammad M, Alamleh H. A Systematic Review of FIDO2 Security, Usability, and Deployment Evidence. Usability, and Deployment Evidence (May 08, 2026). 2026 May 8.
- Bhardwaj P, Sastry N. State of Passkey Authentication in the Wild: A Census of the Top 100K sites. InInternational Conference on Passive and Active Network Measurement 2026 Mar 10 (pp. 319-347). Cham: Springer Nature Switzerland.
- Rudrabhatla CK. Security design patterns in distributed microservice architecture. arXiv preprint arXiv:2008.03395. 2020 Aug 7.
- Verbitskiy I. Node. js security. Cyber Security: A Peer-Reviewed Journal. 2017 Jan 1;1(2):175- 86.
- Biryukov A, Dinu D, Khovratovich D, Josefsson S. RFC 9106: Argon2 Memory-Hard Function for Password Hashing and Proof-of-Work Applications.
- Badhe R, Kuai A, Liu L, Kang H, Truong D, Devadhar C, Akella P, Xue K, Yu AF, Tan TS. Obuhersys: Dynamic Analysis of Cryptographic API Misuse in Node. js. In2024 IEEE MIT Undergraduate Research Technology Conference (URTC) 2024 Oct 11 (pp. 1-5). IEEE.
- Segala A. Essential Cryptography for JavaScript Developers: A practical guide to leveraging common cryptographic operations in Node. js and the browser. Packt Publishing Ltd; 2022 Feb 28.
- Bhoi A, Nayak S, Sahoo B. Learning Club: A FULL STACK PLACEMENT PREPARATION PLATFORM USING MERN STACK.
- Yusop MI, Kamarudin NH, Hasan MK. A Unified FIDO2-Based Passkey Authentication Model for Seamless User Access. In2025 International Conference on Electrical, Communication and Computer Engineering (ICECCE) 2025 Aug 27 (pp. 1-8). IEEE.
- Zhang B, Jiang X, Hu X, Gan Z, Yu B, Wang S. AuthM: A FIDO2/WebAuthn extension for hardware-free web authentication. Journal of Information Security and Applications. 2026 Sep 1;101:104514.
- Gopal S. Building a robust OAuth token based API Security: A High level Overview. arXiv preprint arXiv:2507.16870. 2025 Jul 22.
How to cite this article
@article{TiwariAK2026,
author = {Ankit Kumar Tiwari and Hardik Srivastava and Vaibhav Baishkhiyar and Shikhar Gupta},
title = {A Comparative Study of JWT and Web Authn for Password less Authentication in MERN Stack Applications},
journal = {International Journal of Electrical Power System and Technology},
year = {2026},
volume = {12},
number = {02},
url = {https://journalspub.com/publication/ijepst/article=26892}
}