01
Distributed auth without a shared session store
- Problem
- Six services need to trust the same identity. A shared session table or an introspection call to auth-service would couple every request to one service being up, and turn auth into a bottleneck.
- Decision
- auth-service signs RS256 JWTs and exposes the public keys at /.well-known/jwks.json. Every other service holds only the public key material and verifies tokens locally, with no callback to auth on the request path.
- Tradeoff
- Verification is stateless and fast, but JWTs can't be revoked mid-life. I accepted that for short-lived access tokens, paired with refresh tokens stored server-side in Postgres, which is where revocation actually happens.
- Outcome
- Catalog, order, and ws services can restart or scale independently; the only shared secret in the system is a public key.

