3 ms·
I am curious, why will you not use OAuth 2 userinfo endpoint which can serve a lot more detail and keep claims in JWT simpler and lightweight.
by abhishektwr 6y ago
I am curious, why will you not use OAuth 2 userinfo endpoint which can serve a lot more detail and keep claims in JWT simpler and lightweight.
- quaffapint 6y agoIf you can just pass around the JWT you can save a network call. I would say the size of the JWT wouldn't matter as much as that call.
- abhishektwr 6y agoYou still have to make network calls to obtain public key (JWKS) to validate token signature. Unless you are using shared private keys. With userinfo you will know if token is invalidated or not. I guess it also depends on use case. If you are in domains such as banking with elevated security requirements, then probably you want to hit userinfo endpoint else you can continue with token validation with cached or stored keys.
- jepcommenter 6y agoYou don't pull JWKS on every request