top | item 44762764

(no title)

danscan | 7 months ago

Haven't heard of PASETO, but I'll check it out. I'd say JOSE is an implementation detail of what I'm advocating for, so very open to alternatives.

discuss

order

JimDabell|7 months ago

JWTs and JOSE have a bad reputation for footguns and ignoring modern cryptographic principles.

PASETO is the “mostly fixed” version of JWTs, but if you’re looking for something with more features, biscuits are quite interesting:

https://www.biscuitsec.org