-
@mountain_ghosts depends on what you mean by "JWT itself". as a technology for the auth provider to tell me that a user with id X should be able to perform Y actions between Z and --wait, i should've started my letters a bit earlier-- W... yeah, the payload being in a standard format helps.
-
@mountain_ghosts as a technology for signing a small blob to be passed around, eg in HTTP headers? no, it doesn't.