DEV Community

Discussion on: What is really the difference between Cookie, Session and Tokens that nobody is talking about ?.

 
andreidascalu profile image
Andrei Dascalu

Not necessarily, since tokens expires. You can, if you want to, but you don't have to. Tokens should have short lifespans like a few minutes and extend their lives through refresh. You don't need to revoke a token for a few minutes, just flag the account to temporarily deny renewal.