Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Discord does this, if you change your password it invalidates your Authentication JWT


Discord user tokens are not JWT: https://user-images.githubusercontent.com/34555296/120932740...

Unless your Discord server is actually a spacebar server, in which case they are JWT: https://github.com/spacebarchat/server/blob/master/src/util/...


Oh, I didn't look closely and thought it matched (because of the dots) but yeah it doesn't start with "ey".

Thanks for the information, it's good to know that the token contains the user id inside of it.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: