3 ms·
Sure! Briefly, we use JWT access tokens which are used for session verification. JWTs can be verified using just a secret key which can be stored in memory. Hen
by rishabhpoddar 6y ago
Sure! Briefly, we use JWT access tokens which are used for session verification. JWTs can be verified using just a secret key which can be stored in memory. Hence, no network calls = < 1MS latency.
However, there are issues with using just a JWT, like inability to revoke them or bottlenecking all user security on one secret key. To solve those and other issues, we use rotating refresh tokens. More about this here: https://supertokens.io/blog/are-you-using-jwts-for-user-sessions-in-the-correct-way https://supertokens.io/blog/are-you-using-jwts-for-user-sess...