4 ms·
JWT as a term used to describe signed material should considered harmful (source: me) It's basically just signed authentication material Use it when you need
by kache_ 4y ago
JWT as a term used to describe signed material should considered harmful (source: me)
It's basically just signed authentication material
Use it when you need to keep your authentication layer horizontally scalable & stateless
Use it when you're transferring trust to an untrusted system, acting on behalf of a user (SAML, OAuth, OIDC)
that's it
It's just signed material
data size limitation (from the blog) is a big meme (source: me). Just pack it into a protobuf lmao
eventual consistency of a stateful session will hurt you btw
yes yes yes I know. The grey bears gave us protocols, rfcs, etc. MUH PROTOCOLS. just give me a private key and a bud light dude
the protocols are important for oidc/oath/saml
JWT ISN"T A PROTOCOL
i'm tired, I should go sleep