BackendSecurity

JWT

Also written as JSON Web Token

A compact, signed token format commonly used to verify a logged-in user's identity across requests without the server storing session state.

Think of it like

Like a wristband stamped at a festival's entrance — show it at any gate inside and staff can verify you paid, without radioing back to the ticket booth.

Junior or senior?

Junior sounds like

Doesn't realize a JWT can't be revoked before it expires.

Senior sounds like

Has a real answer for how their system handled logout or a compromised token despite that.

Ask them

“How did your system handle revoking a JWT before it naturally expired — say, after logout or a compromise?”