Hacker News new | ask | show | jobs
by uticus 980 days ago
> The point of JWT vs opaque tokens is that you can just inspect the token itself to derive permissions without hitting any sessions in DB, right?

No. Focus on “token” instead of “JWT.” JWT is just a standard.

1 comments

Are you saying tokens can't be opaque?