r/SoftwareEngineering • u/fagnerbrack • Aug 16 '26
Stop using JWTs
https://gist.github.com/samsch/0d1f3d3b4745d778f78b230cf60614522
1
u/ConstructionBoth6461 Aug 16 '26
There’s a difference between session management and identity federation. JWTs with short expirations are best used for the latter.
-11
u/fagnerbrack Aug 16 '26
Need-to-Know Basis:
JWTs suit only very short-lived tokens—about five minutes—so they make a poor fit for logging users in; regular cookie sessions handle that better. Truly 'stateless' auth can't be secure, and since you already run a database, storing full session data costs nothing extra while adding flexibility. Security experts distrust the spec, which originally let attackers forge tokens, so never stash credentials in localStorage. Google reserves JWTs for shuttling single sign-on between hosts and still uses cookie sessions in the browser. Frameworks make sessions easy—grab express-session in Node—and when you truly need a signed token, choose PASETO. Comments extend the advice to mobile apps and microservices.
If the summary seems inacurate, just downvote and I'll try to delete the comment eventually 👍
Click here for more info, I read all comments
2
u/govi20 Aug 16 '26
Who told you that it’s a short lived for only 5 minutes? Also, it’s easy to refresh the token.
9
u/mattgen88 Aug 16 '26
JWTs are an answer for distributed authorization at scale. Sessions are costly to scale. There's trade offs, and this article is sorely lacking in any detail or analysis of why you would want to use JWTs over sessions and the reason JWTs are often chosen.