Great talk from @rdegges from the @oktadev team on JWTs. youtube.com/watch?v=JdGOb7Ax… Takeaways: don't use them for my general authentication and authoerization. do use them for password reset.
1
or just use auth0 and trust their solution.
2
1
auth0 uses JWTs like everyone else :o
1
1
Does Okta? So you'd recommend rolling my own solution with JWTs for password reset and make sure to keep using cookie sessions for the other stuff?
2
Also, for what it's worth, I think the best long term solution is for the OIDC working group to change the specs.
1
1
What's the chances that's going to happen anytime soon? Maybe my time in the cryptocurrency community has jaded me on changes happening as soon as people would like lol
1
There are some big changes coming in the OAuth/OIDC community, but moving away from JWTs is not one of them. Like most things, if you know how to use them properly, JWTs are fine, which is why it's usually the best bet to go with a major provider's implementation.

Dec 8, 2019 · 11:37 PM UTC

1
2