Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's not clueless or sloppy. They are most likely using https://en.wikipedia.org/wiki/JSON_Web_Token which is a well-defined standard and extremely common in the authentication world because it makes a ton of sense. It lets your authentication server be mostly stateless instead of storing tons of sessions unnecessarily.


Never heard JWT pronounced "jot", I've always sounded it out letter by letter. But nor have I ever considered encoding a JWT into a URL!




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: