hn • r/hackernews
Comment on: Don't use JSON web tokens for sessions
You cannot invalidate JWT tokens This is simple not true.
Developers struggle with the inability to invalidate JWTs, leaving sessions vulnerable and complicating security workflows. TokenGuard offers a lightweight, on‑demand revocation mechanism that instantly invalidates tokens, supports short‑lived sessions, and integrates seamlessly with existing authentication stacks.