Discussion on: JSON web tokens are NOT meant for authenticating the same user repeatedly: Use session tokens instead

being really precise, true, i did not do a formal proof on that.. anyway, for the moment it is not known how to revoke such tokens without state, should it be possible... so to practical effects, its the same

