T
20

Signed JWTs and the paywall that changed my mind

Switching to short-lived access tokens with a rotating signing key cut our leaked credential fallout window from 14 days to 4 hours last quarter. The trick was logging which key ID got revoked and blocking it at the gateway before the token even reached the auth service. Anyone else using token versioning to force client updates instead of just waiting for expiry?
0 comments

Log in to join the discussion

Log In
0 Comments

No comments yet

Be the first to share your thoughts on this discussion.