Hacker News new | ask | show | jobs
by callahad 214 days ago
Step 5.2; the browser binds the KB-JWT to the site it's on, so Site A would receive a JWT that is only valid for Site A.