|
|
|
|
|
by andrewstuart2
3267 days ago
|
|
Do you have any further info on why you so strongly recommend against JWT? My MO has been to know and understand the standard, what it provides (e.g. signed assertions a la SAML, albeit easier on the eyes) and what it does not (e.g. encrypted body without adding your own JWE), and to use it accordingly. This is probably the first I've heard from someone I know is more than just some random HN commenter that JWT is not recommended. |
|