I am implementing a sign in with google feature for a website. I have managed to log the user in with the Google Javascript API. It it stated by google that once we get the tokenID, we have to verify it in the backend server, in order to verify that the current signed in user is valid.
https://developers.google.com/identity/sign-in/web/backend-auth
I have managed to implement the server side verification, the doubt that I have is that do I have to verify the tokenID in the back end for every request by user ?, or should I validate it for every action by the user ?or is there an another approach to this ?
Can some one point me in the correct path ? Thanks