Doug Wilson
Oct 16, 2021

--

Please repeat after me: "JWT is *not* just for user authentication. JWT is *not* just for user authentication. JWT is *not* just for user authentication."

Signed JWTs can assure the receiver (client) of the sender's (server) identity and vice versa, providing the basis for provable non-repudiation.

Encrypted JWTs can provide an additional layer of security for sensitive data in addition to a secure channel.

Understood (ahem) and used properly, JWTs can provide all kinds of important benefits.

But, yeah ... Ethereum.

Muting this nonsense.

--

--

Doug Wilson
Doug Wilson

Written by Doug Wilson

Doug Wilson is an experienced software application architect, music lover, problem solver, former film/video editor, philologist, and father of four.

Responses (2)