I am using Rails API to generate a JWT on user login. Now I need to persist this token. After some reading, I found out that there are two ways of doing this. I can either use local storage or cookies. They both have the problem of XSS and CSRF resp...Read more

JWT (JSON Web Token) seems like the new standard for authentication. JWTs have lots of benefits, but are riskier when compared to HTTP sessions. What's your opinion about JWTs? Would you use them in your application?

49 votes

Closed · Final Results

From Introduction to JSON Web Tokens : JSON Web Token (JWT) is an open standard (RFC 7519) that defines a compact and self-contained way for securely transmitting information between parties as a JSON object. This information can be verified and trus...Read more

