Can you talk a bit about the tech stack behind this? I see <1ms API responses which is very impressive, curious to hear more about the implementation.
However, there are issues with using just a JWT, like inability to revoke them or bottlenecking all user security on one secret key. To solve those and other issues, we use rotating refresh tokens. More about this here: https://supertokens.io/blog/are-you-using-jwts-for-user-sess...