DZone

The topic has been discussed many times, on hacker news, Reddit, blogs. And the consensus is – DON’T USE JWT (for user sessions).

And I largely agree with the criticism of typical arguments for the JWT, the typical "but I can make it work…" explanations and the flaws of the JWT standard.

Source: DZone