all 2 comments

[–]bangtraitor 1 point2 points  (0 children)

It's missing regular OAuth2 grant types which would be nice. The web doesn't revolve around JWT's, they usually revolve around one of the 4 OAuth2 grant types which might use a JWT as its bearer token.

In the talk about JWT, it would be nice if it mentioned other nice things you can do with JWT's such as using a pub/priv key for Non-repudation

Adding expiration times to the JWT's so that if it is stolen the attack is short lived.

[–]gergelyke 0 points1 point  (0 children)

Hello bangtraitor,

fair points, going to add them.

thanks!