Storing data inside JWT token or fetching a fresh data every request

Viewed 40

In an attempt to secure a backend using JWT token over cookies.
It is not clear to me what data is safe to store inside the token/cookie.

for example in the specific case where a check of parameters like policy role, and user license type is needed.

will it be safe to store them inside the JWT token?
OR.
Store only the user_id and get a fresh data from the storage (DB/memcached)?

Thank you

0 Answers
Related