I would like to know why any authentication(JWT, etc...) tokens are suggested to send only as Header, but not as a body parameter?
- Is there any performance issue while handling them from header vs body?
- Is there any security concern?
- Or its just a common practice that's just followed by the community?