Hacker News new | ask | show | jobs
by ascotan 2315 days ago
ergo: if it's ok to have an un-revocable insecure session - use JWT tokens.
1 comments

Or use JWT + OpenID Connect in a centralized mode, as the article explains toward the end.