3 ms·
> No one should be using JWT I've heard criticisms of JWT -- mostly around the lack of ability to revoke a JWT. One could then introduce a refresh token with
by switz 6y ago
> No one should be using JWT
I've heard criticisms of JWT -- mostly around the lack of ability to revoke a JWT.
One could then introduce a refresh token with a longer ttl, which can be revoked on the server. But of course then you lose some of the statelessness that JWT benefits from.
But still, it seems like a reasonable approach to authentication to me. I can authenticate with several services if need be, and I can check locally if my token is 'likely' valid.
Care to expand why you think one shouldn't use JWT tokens?