Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

if your frontend is interrogating the jwt you're doing it wrong


Isn't it pretty common to read the expiration so you know when to refresh tokens?


It is, among other things like username or user e-mail address.

This is also, together with backend scalability, a major selling point for JWTs. Otherwise one might just as well use regular session ids in cookies.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: