Dev iconDevSep 11, 2026 ~1 min source read

Designing a User Management system with JWTs, Ktor, and Exposed

Every app eventually needs to answer two questions: "who is this person?" and "what are they allowed to do?" Many tutorials either focus on integrating a specific authentication provider like Auth0 or Cognito, or else discuss low-level details like password hashing algorithms. Both of those stop short of the real question we should be asking ourselves: who actually is this person, and what does that mean in terms of how we manage their data and access?

Designing a User Management system with JWTs, Ktor, and Exposed

Share this story

Send the public story page.

Useful takeaways from this story.

Both of those stop short of the real question we should be asking ourselves: who actually is this person, and what does that mean in terms of how we manage their data and access?

It refers to the actual human (or machine) interacting with your system, who takes actions to request and change data within it.

This may sound like a subtle distinction but it matters more than it might seem, and this post will help you understand the difference between identity, authentication, and authorization.

Building the complete brief

The page is ready to read now. The fuller skim-friendly version will appear here automatically.

The useful part

Both of those stop short of the real question we should be asking ourselves: who actually is this person, and what does that mean in terms of how we manage their data and access? This may sound like a subtle distinction but it matters more than it might seem, and this post will help you understand the difference between identity, authentication, and authorization. This post is part of a series on the Vesper Design Diaries, building a Production-Grade KMP App on a Bootstrap Budget.

How it works

  • It refers to the actual human (or machine) interacting with your system, who takes actions to request and change data within it.
  • See the Series Introduction for context on the Vesper app and this blog series.
  • Authorization These words get often used interchangeably, but they describe fundamentally different problems.
  • In many cases, apps will use something like your email address to identify you as a human, since emails are something that is ubiquitous and stable.

Details worth keeping

Every app eventually needs to answer two questions: "who is this person?" and "what are they allowed to do?" Many tutorials either focus on integrating a specific authentication provider like Auth0 or Cognito, or else discuss low-level details like password hashing algorithms. Identity is the simple fact of who is using the app. This is a distinctly non-technical concept here.

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app