3 ms·Because then you have all the headaches of JWT, without any of the benefits of stateless auth tokens.by schwap 7y agoBecause then you have all the headaches of JWT, without any of the benefits of stateless auth tokens.TobiasA 7y agoWhich headaches would that be?dewey 7y agoThat you have to keep a white/blacklist if you want to revoke a token.mychael 7y agoBlacklisting is only half the problem. Trying to emulate the same UX of regular sessions (staying logged-in etc) is the bigger pain point.