Hacker News new | ask | show | jobs
by digitalpacman 3658 days ago
It's so that if the JWT is stolen in transit, the thief only has access to the token for a shorter period of time. This is why they should expire quickly. Whether or not you think that matters, is not up for debate. That's how it is.