jwt versus opaque tokens for api authentication
Grzegorz Kowalczyk
·4023 views
Hey everyone, I'm trying to figure out the best way to handle authentication for a new service. We're thinking about using JWTs because they're stateless, but I'm worried about how to revoke them and the hassle of managing keys. Then again, using opaque tokens with a central auth service seems easier for revocation, but I'm concerned it could slow things down. What have you all found works best? Any hidden problems or tips you've learned?
23 comments