20
Signed JWTs and the paywall that changed my mind
Switching to short-lived access tokens with a rotating signing key cut our leaked credential fallout window from 14 days to 4 hours last quarter. The trick was logging which key ID got revoked and blocking it at the gateway before the token even reached the auth service. Anyone else using token versioning to force client updates instead of just waiting for expiry?
0 comments
Log in to join the discussion
Log In0 Comments
No comments yet
Be the first to share your thoughts on this discussion.