> I would not try to cram JWT-s into cookies they are too big, but maybe these days nobody cares about the extra bytes
Why does the length matter compared to when they are sent with cookies or with a special header?
Why does the length matter compared to when they are sent with cookies or with a special header?
Or many usually have separate domain/subdomain names for API and static content in the first place.
I think having a separate prefix/subdomain would be generally good practice for defining scope which should be authed as well.