HN Hall of Fame Weekly email

JSON Web Tokens should be avoided

paragonie.com Essays & writing Essays & articles Security & privacy Candidate
Screenshot of paragonie.com captured 2026-07-20
Page preview · captured 2026-07-20

Resurfaced independently across 3 calendar years, with breakout response in 3 of them.

submissions
3
submitters
3
observed span
2017–2021
peak thread · 297 comments
386 pts
latest 20+ return · 2021-07-12
84 pts

Submission timeline

2007–2026

One slot for every year since HN launched. Height is that year's peak points; orange marks a 100+ point or 50+ comment breakout. Select a bar to open its strongest thread.

First comments on top threads

HN comment order

The criticisms of JWT seem to fall into two categories: (1) Criticizing vulnerabilities in particular JWT libraries, as in this article. (2) Generally criticizing the practice of using any "stateless" client tokens. Because there's no great way to revoke them early while remaining stateless, etc. The problem is that both of these groups only criticize, neither of them can ever seem to actually recommend any alternatives. I could care less about JWT per se. I'm happy to implement a similar…

If you, like me, prefer HN comments over articles: The author does not just complain about JOSE and JWT but he also designed an alternative, PASETO: https://paseto.io/ Here's a nice PASETO write-up from Okta, a reputable third party: https://developer.okta.com/blog/2019/10/17/a-thorough-introd... PASETO looks excellent to me, in that it's proper developer friendly and makes it hard for non crypto nerds like me to shoot themselves in the foot. I can't wait for it to replace JWT in popularity.

We're developing a simply secure alternative, called PASETO (Platform-Agnostic Security Tokens). D. R. I. N. K. Y. O. U. R. O. V. A. L.... Hey wait a minute, this secret message is just an advertisement!

al2o3cr·84-point thread·

The first top-level comment from each of the four biggest threads, in HN’s own order. Excerpts are shortened; open a comment for full context.

Breakout years
3

100+ points or 50+ comments

Total points
643

reference only — not used in Hall rules or ranking

Total comments
423

reference only — not used in Hall rules or ranking

Every submission

DateTitle as submittedByPointsComments
2017-03-14JSON Web Tokens should be avoidedFirst breakout · Best threadCiPHPerCoder386297
2020-02-19Javascript Object Signing and Encryption is a Bad Standard (2017)xenocratus17355
2021-07-12JavaScript Object Signing and Encryption is a bad standard (2017)Latest 20+ point returnIggleSniggle8471