Hapi Auth with JSON Web Tokens (JWT)
The simplest authentication scheme/plugin for
Hapi.js apps using JSON Web Tokens.

Install from NPM
npm install hapi-auth-jwt2 --save
basic usage example to get started:
var Hapi = require('hapi');
var JWT = require('jsonwebtoken');
var port = process.env.PORT || 8000;
var secret = 'NeverShareYourSecret';
var people = {
1: {
id: 1,
name: 'Anthony Valid User'
var token = JWT.sign(people[1], secret);
var validate = function (decoded, callback) {
if (!people[decoded.id]) {
return callback(null, false);
else {
return callback(null, true);
var server = new Hapi.Server();
server.connection({ port: port });
server.register(require('hapi-auth-jwt2'), function (err) {
server.auth.strategy('jwt', 'jwt', true,
{ key: secret, validateFunc: validate });
method: "GET", path: "/", config: { auth: false },
handler: function(request, reply) {
reply({text: 'Token not required'});
method: 'GET', path: '/restricted', config: { auth: 'jwt' },
handler: function(request, reply) {
reply({text: 'You used a Token!'})
.header("Authorization", request.headers.authorization);
Run the server with: node example/server.js
Now use curl to access the two routes:
No Token Required
curl -v http://localhost:8000/
Token Required
Try to access the /restricted content without supplying a Token
(expect to see a 401 error):
curl -v http://localhost:8000/restricted
Now access the url using the following format:
curl -H "Authorization: <TOKEN>" http://localhost:8000/restricted
A here's a valid token you can use (copy-paste this command):
curl -v -H "Authorization: eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpZCI6MSwibmFtZSI6IkFudGhvbnkgVmFsaWQgVXNlciIsImlhdCI6MTQyNTQ3MzUzNX0.KA68l60mjiC8EXaC2odnjFwdIDxE__iDu5RwLdN1F2A" \
That's it.
Write your own validateFunc
with what ever checks you want to perform
on the decoded token before allowing the visitor to proceed.
- (required) a the function which is run once the Token has been decoded
signature function(decoded, callback)
- is the decoded JWT received from the client in request.headers.authorizationcallback
- (required) a callback function with the signature function(err, isValid)
- an internal error.valid
- true
if the JWT was valid, otherwise false
While making Time we want to ensure
our app (and API) is as simple as possible to use.
This lead us to using JSON Web Tokens for Stateless Authentication.
We did a extensive research
into existing modules that might solve our problem; there are many on NPM:

but they were invariably too complicated, poorly documented and
had useless (non-real-world) "examples"!
So we decided to write our own addressing all these issues.
Don't take our word for it, do your own homework and decide which module you prefer.
Guiding Principal
"* perfection is attained not when there is nothing more to add,
but when there is nothing more to remove * " ~
Antoine de Saint-Exupéry
Why hapi-auth-jwt2 ?
The name we wanted was taken.
Think of our module as the "new and simplified version"
Useful Links
For more background on JWT see our post:
Hapi.js Auth
We borrowed code from the following: