Why Authorization/Authentication Tokens are suggested to send only as Header

Viewed 24

I would like to know why any authentication(JWT, etc...) tokens are suggested to send only as Header, but not as a body parameter?

  1. Is there any performance issue while handling them from header vs body?
  2. Is there any security concern?
  3. Or its just a common practice that's just followed by the community?
0 Answers
Related