Hacker News new | ask | show | jobs
by marcosdumay 1363 days ago
> Now, if you want to talk about Oath2 or OIDC then maybe there's a different argument to be had.

I imagine that is the main argument. People use JWT because it's standardized on the authentication protocol... The same authentication protocols that are horrible in many more ways than simply using a bad token format.

Yet everybody jumped into them when Google commanded.