What about if the JWT is created by Cognito. Then sent to a node/express API. The secret does not go with it so no comparison can be made.

In this case, is storing it in the DB and comparing it the best solution?

gravity well (Rob Tomlin)
gravity well (Rob Tomlin)

Written by gravity well (Rob Tomlin)

Software Engineering Manager. Explorer, learner, teacher, and more

No responses yet