Apr 14, 2021
The more common technique is the JWT being generated on the front end like Cognito or Auth0.
However, if you do use this method, you should tell the users where to keep to Secret. If you upload this to GitHub you’ll probably get flagged.