3 ms·
JWTs were never designed for session management. Their primary purpose is to transfer information whose origin can be verified. Period. The idea that they are
by andychiare 3mo ago
JWTs were never designed for session management. Their primary purpose is to transfer information whose origin can be verified. Period.
The idea that they are related to sessions is, unfortunately, a very common misconception. I wrote an article about this some time ago: https://dev.to/andychiare/sessions-tokens-and-rocknroll-4pdc https://dev.to/andychiare/sessions-tokens-and-rocknroll-4pdc