Comment by catlifeonmars

Comment by catlifeonmars 4 days ago

1 reply

Good call. I said OAuth but what I meant was OIDC and specifically JWT. OAuth (not OIDC) implementations MAY use opaque access tokens that require server side state to validate.