Discussion about this post

User's avatar
Ben's avatar

Hey,I wanted to raise a point regarding the JWT authentication flow depicted in the GIF. The flow shown, termed "Implicit Flow" [1], is no longer recommended and is, in fact, considered deprecated. The preferred approach is the Authorization Code Grant [2], enhanced with the Proof Key for Code Exchange (PKCE) extension [3].

[1] https://datatracker.ietf.org/doc/html/rfc6749#section-1.3.2

[2] https://datatracker.ietf.org/doc/html/rfc6749#section-1.3.1

[3] https://www.rfc-editor.org/rfc/rfc7636

Yoyo's avatar

The breakdown of symmetric vs. asymmetric signing is exactly what I needed to visualize—I always struggled to explain why the public key doesn’t compromise the token. I’ve been burned by JWTs expiring mid-session, and I’ve found that testing edge cases with the payload helps a lot; I use a tool like https://literalkit.com/superscript-generator to quickly format my claims for readability before debugging. It’s a small habit, but it saves me from typos in headers.

7 more comments...

No posts

Ready for more?