Hacker News new | ask | show | jobs
by infamousjoeg 1352 days ago
Exactly this. They just need to validate the JWT signature against a JSON Web Key Set (JWKS). There's no need to store the data.