Store the JWT in an `HttpOnly`, `Secure` cookie with `SameSite: 'Lax'` or `'Strict'` and an appropriate expiration. Do not put access tokens in `localStorage`, `sessionStorage`, or Client Component props. Read and verify the cookie in middleware and in a server-side DAL/session helper before rendering protected data. For Server Actions and Route Handlers, also validate the request origin to reduce CSRF risk.
Installs into .claude/skills of the current project.
Are you the author of Nextjs Authentication?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/hoangnguyen0403-nextjs-authentication-agent-skills-standard)
# JWT storage
Store the JWT in an `HttpOnly`, `Secure` cookie with `SameSite: 'Lax'` or `'Strict'` and an appropriate expiration. Do not put access tokens in `localStorage`, `sessionStorage`, or Client Component props. Read and verify the cookie in middleware and in a server-side DAL/session helper before rendering protected data. For Server Actions and Route Handlers, also validate the request origin to reduce CSRF risk.