How do you revoke a JWT before it expires?
Assesses fundamental understanding of Authentication & Authorization conventions, runtime behavior, and memory/performance considerations.
Hiring managers look for precision, avoidance of ambiguous jargon, and ability to explain trade-offs under real production conditions.
A stateless JWT cannot be un-issued, so revocation needs supporting state.
Options:
- Denylist: store revoked token identifiers (
jti) until theirexp, and check on each request. Simple but adds a lookup and grows with volume. - Token version or
pwd_atclaim: keep a per-user counter or password-change timestamp in the user record; reject tokens whose claim is older. A single update revokes all of a user's tokens. - Short access tokens plus refresh-token revocation: keep access tokens to minutes and revoke the refresh token server-side, so the session dies quickly. This is the most common production approach.
- Central introspection: resource servers call the authorization server (as with opaque tokens) to validate, trading statelessness for control.
if (token.exp < now) reject
if (denylist.has(token.jti)) reject
if (token.ver < user.tokenVersion) reject
For immediate global logout, the version or session-store approach is cleaner than a large denylist. Cache validation results briefly to limit overhead.
Candidate Response Strategy & Interview Tips
- Start with a concise one-sentence summary: Deliver a direct, confident answer first before expanding into nuances.
- Demonstrate real-world trade-offs: Discuss where this approach excels and when you would avoid it in production systems.
- Discuss complexity & edge cases: Proactively explain time/space complexity or boundary conditions (null values, scale limits).
- Prepare for interviewer follow-ups: Technical hiring panels frequently probe deeper into concurrency, backward compatibility, or alternative libraries.