BackendSecurity
JWT
Also written as JSON Web Token
A compact, signed token format commonly used to verify a logged-in user's identity across requests without the server storing session state.
Think of it like
Like a wristband stamped at a festival's entrance — show it at any gate inside and staff can verify you paid, without radioing back to the ticket booth.
Junior or senior?
Junior sounds like
Doesn't realize a JWT can't be revoked before it expires.
Senior sounds like
Has a real answer for how their system handled logout or a compromised token despite that.
Ask them
“How did your system handle revoking a JWT before it naturally expired — say, after logout or a compromise?”