2 ms·
What do you mean here? Encoded in their API? And If they don’t like JWT, why don’t they use something else?
by throwaway3157 7y ago
What do you mean here? Encoded in their API?
And If they don’t like JWT, why don’t they use something else?
- lvh 7y agoMajor IdPs tend to provide an endpoint where you can send them the JWT, they validate it and return its contents as a plain JSON response. You're effectively trading JWT parsing for HTTPS. They can't walk JWT back now without breaking existing apps, because parsing it yourself was advertised as an option.