How the User Token Workflow Works
User tokens are used to identify users to third parties so challenges completed using those services can be saved to a user’s account.
How they are Created
Section titled “How they are Created”User tokens are used to submit challenges completed through CodeRoad and freeCodeCamp OS, including Relational Database and Back End Development and APIs courses and projects.
A token gets created when a signed-in user clicks “Generate User Token” in a challenge’s setup instructions. The user then clicks “Copy User Token” and follows the instructions to add it to their course environment. Starting a course or project does not generate a token.
When they Get Deleted
Section titled “When they Get Deleted”A user token will be deleted when a user resets all their progress, deletes their account, or manually deletes the token using the widget on the settings page. Generating a new token also deletes any existing tokens for that user. Signing out of freeCodeCamp does not delete the token.
How they Work
Section titled “How they Work”Tokens are stored in a UserToken collection in the database. Each record has a unique _id, exposed as id in Prisma, and a userId that links to the user’s account in the user collection. The API signs the token ID in a JWT and sends it to the client when it’s created.
The course environment sends that JWT to the /coderoad-challenge-completed endpoint in the coderoad-user-token header when a challenge is completed. The API verifies the JWT and looks up the token record to identify the user.
Practice challenges are saved to the user’s completedChallenges. For certification projects that are not already completed, the API first saves the project to partiallyCompletedChallenges. The user must then submit their public repository URL on the challenge page to complete the project.