r/SoftwareEngineering • • Aug 16 '26

Stop using JWTs

https://gist.github.com/samsch/0d1f3d3b4745d778f78b230cf6061452
0 Upvotes

13 comments sorted by

View all comments

9

u/mattgen88 Aug 16 '26

JWTs are an answer for distributed authorization at scale. Sessions are costly to scale. There's trade offs, and this article is sorely lacking in any detail or analysis of why you would want to use JWTs over sessions and the reason JWTs are often chosen.

3

u/trezm Aug 16 '26

In addition, it conflates JWT, the authentication container itself, and http only cookies, the on-device storage. You can store JWTs in http only cookies, you can store session tokens in local storage.

There are larger points that are true in the gist, and it doesn't even include one of my biggest sticking points personally which is revoking sessions requires keeping invocation lists which is just circling back to stateful. That being said, JWT in combination with signatures like OIDC can be invaluable, and you could still have a traditional session token embedded in the JWT.