Reply

I want to say that some of the folks in the #IndieWeb may be able to chime in on this too, as we try to publish events to our sites where possible

 Like

 Like

 Reply

Yep, the next one is the 4th March https://events.indieweb.org/2020/03/homebrew-website-club-nottingham-FWdZAqhKZBnq - would be good to see you there!

 Reply

Reply to https://github.com/aaronpk/IndieAuth.com/issues

Currently, the format of the tokens provided by IndieAuth.com is a signed JWT (JWS) using HS256.

If we were to update this to be RS256, we could allow clients to treat it as a JWS, not an opaque token that needs to be introspected by the token endpoint.

This could allow clients validating tokens as such to do so much more easily, locally, while reducing load on the token endpoint.

Because token revocation is not widespread at this point, it would enable clients to not need to introspect unnecessarily.

 Reply

I've been seeing some heavy advertising for Tide's business banking so I guess it's worked cause I'm talking about it, but no clue if it's any good πŸ€·πŸ½β€β™‚οΈ