logoalt Hacker News

skhameneh • today at 4:21 PM • 0 replies • view on HN

Other commenters are suggesting you can’t blame the spec for end implementation mistakes, except that’s one of the many issues - JWT being so error-prone is a problem.

I use JWT just for handling of tokens, because it’s so well supported, but I won’t use it for anything more than token storage _because_ it is so vulnerable to mistakes.

The fact that mistakes are so easy to make is indicative of poor design in the spec itself.