top of page

Welcome
to NumpyNinja Blogs

NumpyNinja: Blogs. Demystifying Tech,

One Blog at a Time.
Millions of views. 

Securing Microservices with OAuth 2.0, JWT, and API Gateway

Apr 29, 2025
4 min read

Updated: Apr 30, 2025

A microservice system is an architectural style that helps us build flexible and scalable systems by breaking large applications into smaller, independent services. When building microservices, handling authentication is a significant challenge.


In a traditional monolithic application, there is a user login component where the user logs in with their credentials and accesses the required endpoints. However, when you’re building with microservices, things get complicated easily. Each service is a separate entity and runs on its own, which means each service needs to perform authorization; they all need to know who the user is, what they are allowed to do, and whether the request can be trusted or rejected. In a monolithic setup, that’s usually handled in one place. However, in the case of microservices, you cannot use the same authentication logic for every service.


Here is where tools like JWTs, OAuth 2.0, and API Gateways make things easier. They work together to ensure users are authenticated properly, permissions are granted only when required, and requests are handled smoothly without each service doing redundant work. In this blog, we’ll discuss these technologies and how they fit together.


Why OAuth is ideal for handling delegated access:


When a service in a microservice architecture starts interacting with another service, for example, say there is a user service and a payment service, there should be a way to control which users can access what. In such scenarios, OAuth 2.0 comes into action by enabling the services to verify the user and their access without each service handling it separately.

Let's clarify things here to avoid misunderstanding OAuth 2.0 as a login system. A lot of new developers confuse OAuth with that, but it's more about authorization. Take it in this way: instead of our application asking for someone’s password (which is a terrible idea), OAuth enables apps to request authorization to access the required information on behalf of the user. This way, our app gets what it needs without accessing the user's credentials.


How does OAuth work?

Instead of making our app deal with usernames and passwords (which is risky), we hand that job off to a trusted provider, like Google, GitHub, Auth0, or even a company’s own OAuth system.

Here’s how it usually plays out:

  • You hit a login button that says something like “Sign in with Google.

  • When you click it, you’re taken to Google’s login page, which is nice and secure.

  • You log in, grant a few permissions, and Google sends you back to the app with a special code, which is the authorization code.

  • The app then takes that code and trades it in for an access token, which it uses to talk to APIs on your behalf



And the best part is that your app never touches the user’s password. It just deals with the access token. Since this token only lasts for a small amount of time and only grants specific access, it keeps things secure and real, which is a great win when you are working with lots of microservices.


Flow of Request with OAuth and JWT
Flow of Request with OAuth and JWT

Moving from OAuth 2.0 to JWT in Spring Microservices


Once you have OAuth 2.0 in your system, the next logical step is to use JSON Web Tokens (JWTs) as your access token. This is because JWTs are self-contained; they carry everything needed about a user, right inside the token. This means the microservices do not have to keep pinging a central server to check who the user is; they just decode the token and move on.

In most cases, OAuth 2.0 and JWT are not separate options; they go hand in hand. OAuth 2.0 grants permission, and JWT is the format of your token.


How does JWT work in Spring microservices with JWT?

  1. User/Client Authentication: The user needs to authenticate with the OAuth 2.0 authorization server. After a successful login, a JWT (an access token) is issued by the server to the user/client.

  2. User/client Request with JWT: The JWT token is included in the authorization header when an HTTP request is sent to the Spring microservices.

  3. Spring Security validates JWT: On receiving the request, Spring Security decodes and validates the JWT by verifying the signature, expiration time, and also extracts the details of the user if needed.

  4. Authorization: Based on the role extracted from the user details, the permission to access resources is given or denied.

  5. Process the Request: Once the authorization is done, the request is processed, and a response is sent.


API Gateway


Now that we are securely issuing JWT tokens and using them to protect our microservices, the next step is to see who will be responsible for verifying all these tokens across all the services. If each microservice handles its own validation, there will be a lot of duplication of logic, plus managing authentication and request routing in every service. This is exactly where an API Gateway steps in.

  • API Gateway is a smart entry point to our system. Instead of letting a user hit microservices directly, every request goes through the gateway first.

  • API Gateway checks the incoming JWT token, verifies its validity, and then routes the request to the right service. This way, the same auth implementation is not done across all services.

  • API Gateway also handles extra features like load balancing, retries, request throttling, CORS, and centralized logging.


Best practices to secure API Gateways

API Gateway with JWT
API Gateway with JWT
  • Ensure all communication between the client and API Gateway is done through HTTPS.

  • Implement authentication and HTTPS at the API gateway level instead of individual microservices.

  • Use a centralized authentication server to issue or refresh tokens.

  • Limit the API requests; this prevents excessive API requests from overwhelming upstream services.

  • Monitor the API to catch any potential threats or problems that services face

  • Implement separate API gateways for each use case whenever your app utilizes various connections. This will prevent exposing end-points

  • Manage API, keeping track of the APIs, and removing unused and deprecated old versions



Conclusion

Now that we have learned how OAUTH2.0, JWTS, and API Gateway function together to protect our microservices. Let's build secure services!

Happy learning!

 
 

+1 (302) 200-8320

NumPy_Ninja_Logo (1).png

Numpy Ninja Inc. 8 The Grn Ste A Dover, DE 19901

© Copyright 2025 by Numpy Ninja Inc.

  • Twitter
  • LinkedIn
bottom of page