DZone
The topic has been discussed many times, on hacker news, Reddit, blogs. And the consensus is – DON’T USE JWT (for user sessions).
And I largely agree with the criticism of typical arguments for the JWT, the typical "but I can make it work…" explanations and the flaws of the JWT standard.
Source: DZone