biscuit-based identity and authorization I’m working on https://www.hessra.net/ , an identity + authorization service built around [Biscuits]( https://www.biscuitsec.org/ ) instead of JWTs. The goal is to decompose auth primitives so they’re easier to use in service-to-service cases, while also showing off what Biscuit tokens make possible. JWTs feel like problems waiting to happen. I think biscuits give stronger gua…
(what a word salad that is...)