re: Be careful of the JWT hype train


No role changes or payment status changes might have occurred since the JWT was issued?

Can't we revoke JWT in that case?

By no means a JWT advocate btw.


Then you have a stateful revocation list you have to make available to every server and JWT is no longer stateless.

