DEV Community

Discussion on: Be careful of the JWT hype train

Collapse
 
joelnet profile image
JavaScript Joel

How can you avoid any curious customer don't call console.log() to show the jwt-secret?.

You don't keep secrets in the JWT. Everything in a JWT should be considered public.