@lillichoung gotta look at who is doing the recommending. JWT is very convenient for serverless and vendors.

meanwhile everyone running rails and django set up sessions, send httponly cookies and carry on with their day. the only vendor who does it right is @begin