Force Expiring of JWTs with Refresh Tokens

A concept to stop the bully who somehow stole your JWT.

Why not include a simple reference to the issuing refresh token in the JWT payload for additional validation?

It’s up to you as to what you’d prefer to focus on.

github/@ptboyer React, UI, API Design and other thoughts

github/@ptboyer React, UI, API Design and other thoughts