What are some best practices for authenticating users in a REST API using PHP?

When authenticating users in a REST API using PHP, it is essential to use secure methods to verify the identity of the user. One common practice is to use JSON Web Tokens (JWT) for authentication. This involves generating a token when the user logs in and sending it back to the client. The client then includes this token in the header of subsequent requests to authenticate the user.

// Generate JWT token
function generateToken($user_id) {
    $key = "secret_key";
    $payload = array(
        "user_id" => $user_id,
        "exp" => time() + 3600 // Token expires in 1 hour
    );
    return JWT::encode($payload, $key);
}

// Verify JWT token
function verifyToken($token) {
    $key = "secret_key";
    try {
        $decoded = JWT::decode($token, $key, array('HS256'));
        return $decoded->user_id;
    } catch (Exception $e) {
        return false;
    }
}

// Example of generating and verifying token
$token = generateToken(123);
$user_id = verifyToken($token);
if($user_id) {
    // User is authenticated
} else {
    // Invalid token
}