How do you revoke a JWT before expiry in a multi-instance Spring cluster?
PICTURE THIS: A SENTENCE BECOMES TOKENS
The model does not read letters like humans. It reads these pieces, then predicts the next one.
Simple meaning
Pure stateless JWT cannot be revoked except by waiting.
WHY — Auth instead of guessing?
Why interviewers care about Auth:
question about Auth.
trade-offs, and what you would actually do on a Backend project - not buzzwords.
Name the idea, why it exists, then one short example.
End with when you use it and one common pitfall.
STEPS — What happens with tokens?
Before the model can read a sentence, it goes through these steps:
- 1Pure stateless JWT cannot
be revoked except by waiting.
- 2You keep a denylist
of jti values in Redis until natural expiry, or rotate a user-level token version stored in Redis and embed it in the payload.
- 3Refresh tokens should be
rotated and stored hashed server-side so theft is containable.
- 4Context mix
Attention looks at nearby tokens together.
- 5Next token
The model scores what should come next.
- 6Decode
IDs turn back into readable text.
EXAMPLE — See it in action
Let's see how a real sentence is tokenized (tokens may vary by model):
Note: Actual tokens and IDs depend on the tokenizer (e.g., GPT, Llama, etc.).
Key takeaway
Pure stateless JWT cannot be revoked except by waiting. You keep a denylist of jti values in Redis until natural expiry, or rotate a user-level token version stored in Redis and embed it in the payload.