Tagged articles

Token Revocation

5 articles · Page 1 of 1
Cloud Architecture
Cloud Architecture
Jun 26, 2026 · Information Security

OAuth 2.0 at Billion-Scale: Unified Auth Center Architecture & Pitfall Guide

This article details how to design a unified authentication center that can handle billions of OAuth 2.0 requests, covering layered architecture, token issuance and revocation, refresh‑token rotation, gateway validation, key management, and practical pitfalls to ensure secure, high‑performance identity traffic in production.

AuthenticationHigh ScaleOAuth 2.0
0 likes · 46 min read
OAuth 2.0 at Billion-Scale: Unified Auth Center Architecture & Pitfall Guide
dbaplus Community
dbaplus Community
Dec 29, 2024 · Information Security

Why Many Developers Warn Against Using JWTs for Authentication

This article explains what JSON Web Tokens are, outlines their typical usage flow, and critically examines their drawbacks such as size overhead, redundant signatures, revocation challenges, stale data, lack of encryption, and broader security concerns.

AuthenticationJWTSecurity
0 likes · 6 min read
Why Many Developers Warn Against Using JWTs for Authentication
Shepherd Advanced Notes
Shepherd Advanced Notes
Jul 16, 2024 · Information Security

Why Developers Are Abandoning JWT for Authentication and Authorization

The article examines JWT's benefits such as statelessness and CSRF protection, then details its drawbacks—including revocation difficulty, XSS risk, and token size—and presents practical solutions like blacklists, short lifetimes, and refresh‑token strategies, helping readers decide when to use JWT versus session‑based authentication.

AuthenticationCSRFJWT
0 likes · 14 min read
Why Developers Are Abandoning JWT for Authentication and Authorization