JWT expiration and revocation
Question Variations
- "Can a JWT be revoked without server-side state?"
- "How would you log a user out of every device?"
- "What should happen after refresh-token reuse is detected?"
Why This Is Asked
JWTs can be verified without a session lookup, but that property makes immediate invalidation a design choice rather than a default. Interviewers use this to assess token lifetime design, logout and incident response, refresh-token rotation, and trade-offs between statelessness and control.
Key Concepts
- Expiration: Short-lived access tokens bound the replay window.
- Revocation state: Deny lists, session versions, and introspection add a server-side check.
- Refresh tokens: Rotated, revocable credentials can continue a session without long-lived access tokens.
- Key rotation: Broadly invalidates tokens only when keys are retired and is not a routine logout mechanism.
Question Variations
- “Can a JWT be revoked without server-side state?”
- “How would you log a user out of every device?”
- “What should happen after refresh-token reuse is detected?”