|
|
|
|
|
by d-z-m
980 days ago
|
|
> The point of JWT vs opaque tokens is that you can just inspect the token itself to derive permissions without hitting any sessions in DB, right? As I understand it, de-centralized verification isn't a necessary characteristic of a JWT. There are token constructions that make that a priority, however[0]. [0]: https://www.biscuitsec.org/ |
|