@legitalgorithmswithpeter: JWT vs Session Authentication 🔐 Both keep users logged in, but the server stores identity differently. 🍪 Session Auth = Stateful The server stores the session in memory, a database, or Redis. The client only sends a session ID. ✅ Instant revocation ✅ Easy centralized control ❌ Requires shared session storage at scale 🎟️ JWT = Stateless The token carries claims and is cryptographically signed. Servers can verify it without querying a session store. ✅ Great for distributed systems & APIs ✅ Easy horizontal scaling ❌ Revocation is harder ❌ Token storage can introduce XSS risks The key difference: Session → Server remembers you. JWT → The token carries your identity. And JWT isn’t automatically “more secure.” The right choice depends on your architecture, client type, scaling requirements, and how important instant revocation is. #JWT #Authentication #WebSecurity #BackendDevelopment #SystemDesign
jti stored in redis/dragonfly for the exp at - curr time for remaining ttl and the jti is checked at every request if its not revoked making jwt kinda stateful
2026-09-10 19:58:47
0
derpherderp :
It’s stupid how well I learn from these. Why Peter griffin and why is he so good at teaching me. Please keep making these
2026-09-10 17:15:07
2
DsA :
Wouldn't storing the session id in shared redis easily scale horizontally with little added latency?
2026-09-10 20:29:02
0
kevinogutu181 :
Why is Peter so smart. 😂😂😂
2026-09-10 18:20:45
0
PantsStatusZero :
can do okf?
2026-09-10 17:03:57
0
To see more videos from user @legitalgorithmswithpeter, please go to the Tikwm
homepage.