Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Those are mostly the drawbacks of JWT, less so using stateless sessions altogether.

I found some additional reasons from a page that was linked from that last link here: http://cryto.net/~joepie91/blog/2016/06/13/stop-using-jwt-fo...

  * They take up more space  
  * You cannot invalidate individual JWT tokens
The other reasons seem a bit weaker.

In your opinion, are those also the reasons why you wouldn't use PAST for stateless sessions?



> In your opinion, are those also the reasons why you wouldn't use PAST for stateless sessions?

Yep




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: