Replace JWT, JWE, JWS with PASETO #1215

Closed
opened 2026-03-13 08:28:40 -05:00 by GiteaMirror · 3 comments
Owner

Originally created by @dougg0k on GitHub (May 16, 2025).

Is this suited for github?

  • Yes, this is suited for github

It would help avoid potentially security issues found in the other tokens.

Describe the solution you'd like

Hi,

I would like to suggest replacing all the metions in the title with PASETO.

https://github.com/paseto-standard/paseto-spec

https://permify.co/post/jwt-paseto

https://github.com/auth70/paseto-ts

Describe alternatives you've considered

None

Additional context

None

Originally created by @dougg0k on GitHub (May 16, 2025). ### Is this suited for github? - [x] Yes, this is suited for github ### Is your feature request related to a problem? Please describe. It would help avoid potentially security issues found in the other tokens. ### Describe the solution you'd like Hi, I would like to suggest replacing all the metions in the title with PASETO. https://github.com/paseto-standard/paseto-spec https://permify.co/post/jwt-paseto https://github.com/auth70/paseto-ts ### Describe alternatives you've considered None ### Additional context None
Author
Owner

@dosubot[bot] commented on GitHub (Aug 15, 2025):

Hi, @dougg0k. I'm Dosu, and I'm helping the better-auth team manage their backlog and am marking this issue as stale.

Issue Summary:

  • You proposed replacing JWT, JWE, and JWS with PASETO to address potential security vulnerabilities.
  • Your suggestion is supported by references to the PASETO specification and related materials.
  • No alternative solutions or further discussion have been provided since your initial proposal.
  • The issue remains unresolved with no recent activity.

Next Steps:

  • Please let me know if this issue is still relevant to the latest version of better-auth by commenting here.
  • If I do not hear from you within 7 days, this issue will be automatically closed.

Thank you for your understanding and contribution!

@dosubot[bot] commented on GitHub (Aug 15, 2025): Hi, @dougg0k. I'm [Dosu](https://dosu.dev), and I'm helping the better-auth team manage their backlog and am marking this issue as stale. **Issue Summary:** - You proposed replacing JWT, JWE, and JWS with PASETO to address potential security vulnerabilities. - Your suggestion is supported by references to the PASETO specification and related materials. - No alternative solutions or further discussion have been provided since your initial proposal. - The issue remains unresolved with no recent activity. **Next Steps:** - Please let me know if this issue is still relevant to the latest version of better-auth by commenting here. - If I do not hear from you within 7 days, this issue will be automatically closed. Thank you for your understanding and contribution!
Author
Owner

@dougg0k commented on GitHub (Aug 15, 2025):

Your stale check are useless, since it's based time passed without response rather than actual real considerations.

It should be relevant.

@dougg0k commented on GitHub (Aug 15, 2025): Your stale check are useless, since it's based time passed without response rather than actual real considerations. It should be relevant.
Author
Owner

@dosubot[bot] commented on GitHub (Nov 14, 2025):

Hi, @dougg0k. I'm Dosu, and I'm helping the better-auth team manage their backlog and am marking this issue as stale.

Issue Summary:

  • You suggested replacing JWT, JWE, and JWS with PASETO to address potential security concerns.
  • Relevant references were provided, but no alternative solutions or implementations were proposed.
  • The issue was marked as stale due to inactivity, but you confirmed it remains relevant.
  • No further discussion or resolution has occurred since your last response.

Next Steps:

  • Please let me know if this issue is still relevant to the latest version of better-auth by commenting here.
  • If I do not hear back within 7 days, the issue will be automatically closed.

Thank you for your understanding and contribution!

@dosubot[bot] commented on GitHub (Nov 14, 2025): Hi, @dougg0k. I'm [Dosu](https://dosu.dev), and I'm helping the better-auth team manage their backlog and am marking this issue as stale. **Issue Summary:** - You suggested replacing JWT, JWE, and JWS with PASETO to address potential security concerns. - Relevant references were provided, but no alternative solutions or implementations were proposed. - The issue was marked as stale due to inactivity, but you confirmed it remains relevant. - No further discussion or resolution has occurred since your last response. **Next Steps:** - Please let me know if this issue is still relevant to the latest version of better-auth by commenting here. - If I do not hear back within 7 days, the issue will be automatically closed. Thank you for your understanding and contribution!
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github-starred/better-auth#1215