Hacker Times
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
Rapzid
35 days ago
|
parent
|
context
|
favorite
| on:
Stop Using JWTs
Yeah, hasn't it been "best practice" for a decade or more to treat JWT like a ticket and swap it for a cookie-based session ID in anything browser-like? Then you just do all the cookie session "best practices" to lock it down.
Consider applying for YC's Fall 2026 batch!
Applications
are open till July 27.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: