WebDev
kavi_castelo's profile
kavi castelo@kavi_castelo•Jun 11, 2025
1.7K
Talentboozt's profile
Post cover image

Why I Don’t Use LocalStorage for Tokens — And What I Do Instead

From medium.com•Jun 11, 2025•3m read time

LocalStorage poses security risks for storing JWT tokens due to XSS vulnerability and lack of browser security features. A safer approach uses access tokens stored in memory (lost on page refresh) combined with refresh tokens in secure HttpOnly cookies. This pattern reduces XSS attack surface, ensures session expiry on tab close, and leverages browser cookie security flags. Token rotation further enhances security by invalidating refresh tokens after each use.

10 Comments

Sort:

kavi_castelo's user avatar
kavi castelo
@kavi_castelo
Joined Sep 21. 2022
1.7K
Talentboozt's profile

Talentboozt

Verified

🚀 Engineering the Future | SaaS Architect | Full-Stack Enthusiast | Tech Leader & Innovator

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard