DEV Community

Discussion on: Authentication & Authorization in Microservices Architecture - Part I

Collapse
 
tracker1 profile image
Michael J. Ryan

Would add that you can use asymmetric rsa signing. This is generally safer than a shared secret. I'm fact the authority generating the jwt can share it's public key publicly.

Other considerations are revocation and renewal.