jti
jti, short for JWT ID, is a registered claim in the JSON Web Token (JWT) specification (RFC 7519). It represents a unique identifier assigned to a specific token. The claim is optional but widely used to support replay protection and token lifecycle management.
Purpose and usage: The main purpose of jti is to prevent the same token from being used
Generation and format: jti values should be globally unique for the issuer. Common choices include cryptographically
Limitations and considerations: Replay protection with jti requires state: the issuing service or a central validator
Relation to JWT practice: jti is one of the registered claims in JWT, alongside others such as