Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> having a blocklist of revoked JWT IDs in an in-memory cache (like Redis) can bring back some performance benefits.

Doing this obviates some of the benefits of JWT's statelessness, but for situations where revocation is really important and you can't have that few seconds of JWT validity after a user logs out, this totally works.

My employer has an article about this topic here: https://fusionauth.io/learn/expert-advice/tokens/revoking-jw...



Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: