0

From what I understand, JWTs are used to verify who is logged in. But I also read that sessions do a better job at that.

What I want to know is:
- Should I use JWTs during log in to add an extra layer of security (on top of sessions)?
- What about while registering or signing up?

I still don't understand the purpose of JWTs and if someone could also explain them in very simple terms, that would be gold.

  • This post https://stackoverflow.com/questions/27067251/where-to-store-jwt-in-browser-how-to-protect-against-csrf gives some direction to this question. There is a nested comment from the second answer https://stormpath.com/blog/where-to-store-your-jwts-cookies-vs-html5-web-storage that is pretty good. – david Nov 05 '21 at 00:17

0 Answers0