4 ms·
In the apps I write for my org integrating with the org SSO provider, I treat the JWT tokens mostly like a non-JWT token. Verify the token with the IDP, map the
by blntechie 6y ago
In the apps I write for my org integrating with the org SSO provider, I treat the JWT tokens mostly like a non-JWT token. Verify the token with the IDP, map the token to a specific user and never relying on the JWT payload user info for the resource auth. It takes additional 0.25s during the login process but has never let me down. As the SSO provider was issuing non-JWT tokens few years back, this was the way we went about making sure the user is who they are saying they are and just stuck with the same approach when they moved to JWT tokens.