Thomas Ptacek (respected security web security expert) on why to not use JWTs
news.ycombinator.com
I don't care if you want to use stateless client tokens. They're fine. You shoul... | Hacker News