jwt-authentication ---- using jsonwebtoken npm module to build stateless authentication 1.sign token 2. verify token