No dates yet
Tell us the schedule that would work
We plan batches around demand. Weekend, morning and intensive formats open when enough people ask for them.
Register your interestPut authentication and authorisation on a real API without inventing your own
Designed for
Course curriculum
Duration: 12 guided hours
FoundationSessions 1–2
What you will build
One endpoint secured and one left open, with the filter chain printed and each filter's job named.
Module 1
FoundationSessions 1–2
What you will build
One endpoint secured and one left open, with the filter chain printed and each filter's job named.
Module 1
Learning outcomes
Batches
No dates yet
We plan batches around demand. Weekend, morning and intensive formats open when enough people ask for them.
Register your interestWho teaches this

Vishal Shah
Founder & Principal Trainer
Two decades building and teaching commerce, banking and cloud platforms — still writing code
Detailed course information
Security is the part of a backend most often copied rather than understood. A JWT filter from a blog post works on the happy path and fails in ways nobody notices until an audit.
This course is short and adversarial. You secure an API, then attack it from a second terminal, then fix what broke — and you finish able to say why each control is there.
You need a working Spring Boot API. If you do not have one, Spring Boot & REST APIs comes first and builds the service you will secure here.
Group three of Backend Developer — Java and part of Full-Stack Developer — Java.
Get batch details
Tell us the schedule that would suit you and we will let you know when a batch opens.
Where this leads
Step 3 of 6
Java Full-Stack Developer · 3–4 months
Step 3 of 4
Java Backend Developer · 6–8 months
Need help deciding?