I'm not gonna say JSON Web Tokens are *bad* (if used properly), but I'm also not gonna say they're *great* either. Here's an interesting alternative though: PASETO developer.okta.com/blog/2019…

Oct 17, 2019 · 5:25 PM UTC

1
1
12
Replying to @aaronpk
I can’t say that they make a convincing argument against JWT and their derivatives. Plus I’m not impressed by secrets management that suggests “safely store a shared secret key (maybe in environment variables”