So don't do that - and you're stateless!
I can't recall the last time I used a "Logout" button anywhere. I no longer visit internet caffees...
I can't recall the last time I used a "Logout" button anywhere. I no longer visit internet caffees...
With vanilla JWTs, you have no way to do this! But then if you add revocation checking on top (which people do), your JWTs are no longer stateless.
And once you do you need some state and then JWTs don’t make much sense anymore. There are of course many valid use cases for JWT so “JWT bad” is a very reductive take
Note the auth systems I create usually do not process payment info and contain very little personal information (an email). I still think I'm fine without revocation mechanisms.