Itay Podhajcer
Oct 26, 2021

Unfortunately, I think you have a fundamental assumption that JWT is and authentication mechanism, which is wrong.

JWT is just the token format that's being by authentication mechanisms, such as OAuth/OIDC, or even new emerging standards like Decentralized Identifiers (DIDs) and SIOP.

Those authentication mechanisms provide definitions of flows that cover not just the basic "user identifies to backend" scenario, but more complex scenarios such as establishing trust between two security boundaries.

If you are really interested on decentralized authentication and authorization, I do encourage you to take a look at Decentralized Identifiers, which can actually be used not just for authentication scenarios (you can start here: https://www.w3.org/TR/did-core/).

Sign up to discover human stories that deepen your understanding of the world.

Free

Distraction-free reading. No ads.

Organize your knowledge with lists and highlights.

Tell your story. Find your audience.

Membership

Read member-only stories

Support writers you read most

Earn money for your writing

Listen to audio narrations

Read offline with the Medium app

Written by Itay Podhajcer

Tech expert with 20+ years’ experience as CTO, Chief Architect, and Consultant. 3x Microsoft MVP award winner. Passionate blogger and open-source contributor

No responses yet

Write a response