Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Access tokens are short lived and can easily be revoked (when opaque).

Sending your service credentials to every service is arguably less secure since they can have lesser security or log unwanted things.



Revocation is actually a major problem with JWTs.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: