Baoyuantop commented on issue #12438: URL: https://github.com/apache/apisix/issues/12438#issuecomment-3100804711
For most scenarios, it is more practical and secure only to pass the payload content. Downstream services do not need to handle JWT signature verification, reducing implementation complexity. > I need the actual ID-Token for my use-case. Can you describe this requirement in detail? -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: notifications-unsubscr...@apisix.apache.org For queries about this service, please contact Infrastructure at: us...@infra.apache.org