3 ms·
You can't revoke a singular token but you can change your secret key to revoke every token.
by bweitzman 11y ago
You can't revoke a singular token but you can change your secret key to revoke every token.
- eloisius 11y agoOr, instead of putting the user id in the claims hash, you could have a separate lookup field on the user model explicitly for finding users by JWT. That way, you can have a "log me out everywhere" button on your site. Not quite as smooth as revoking a single authentication, but better than nothing.