ParentFull threadedem·i have been telling teams for years that jwts are only good for one-off processes. they don't even bother to use jewes, sometimes there is no signature validation. no wonder broken authorization is the top 1 security problemView on HN