4 ms·
JWT begs you to use public key because it makes sense for a lot of the use cases that people implement using JWT specifically having a single token issuer while
by davewritescode 10y ago
JWT begs you to use public key because it makes sense for a lot of the use cases that people implement using JWT specifically having a single token issuer while having distributed token validation.
Using a public key algorithms makes also it easier to implement a sane key rollover strategy. I suspect this is the reason that Auth0 pushes their customers to validate tokens with public keys published on their JWKS endpoints.
As for X.509, I agree it kind of sucks but what are the alternatives?
- unscaled 10y agoThe alternative is pushing plain public keys over an authenticated channel. You usually don't need the complexity of X.509. That being said, the aforementioned authenticated channel will more often than not be TLS, which does happen to rely on X.509.