12 Comments
User's avatar
Raul Junco's avatar

Nice breakdown, Saurabh.

JWTs work great for microservices, but sessions still win when you need quick revocation and tighter control.

It's all about trade-offs and context.

Thanks for the article.

Saurabh Dashora's avatar

Thanks Raul. Great point about the session revocation advantage.

NAROTAM KUMAR MISHRA's avatar

Very useful !!

Matheus Ribeiro dos Santos's avatar

thanks for sharing!

Muruga Guru's avatar

Awesome! Great insight!!

Bruno Solon's avatar

Great article Saurabh!

Quick question: when it comes to refresh token, you would store it in a database in order to refresh and create a new JWT, right?

Thanks for sharing it!

Krishna's avatar

Thanks, Saurabh.

Very useful article to read about differences between authentication mechanisms.

Meenakshi NavamaniAvadaiappan's avatar

In customer facing financial applications all this cooked into user session credentials of database and services to know about the good 😊

Adeola's avatar

Great share. As a Frontend Engineer I have seen both work in action for authorization, but JWT is vastly used than Cookies.