Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

What do you mean here? Encoded in their API?

And If they don’t like JWT, why don’t they use something else?



Major IdPs tend to provide an endpoint where you can send them the JWT, they validate it and return its contents as a plain JSON response. You're effectively trading JWT parsing for HTTPS.

They can't walk JWT back now without breaking existing apps, because parsing it yourself was advertised as an option.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: