Hacker News new | ask | show | jobs
by ghayes 919 days ago
You could make your expiration short enough that you are unlikely to need revocation, and allow token exchange (trade an expired token for a new one, and that would include a revocation check)