Store JWT token in cookie
This is my setup: 1 authentication server which gives out JWT token on successfull authentication. Multiple API resource servers which gives information (when the user is authenticated). Now I want to build my ASP.NET MVC frontend. Is it ok to take the token, which I receive after authentication, and put it in a cookie so I can access it with every secured call I need to make? I use the RestSharp DLL for doing my http calls. If it has a security flaw, then where should I store my token? I would use this code for the cookie: System.Web.HttpContext.Current.Response.Cookies.Add(new System.Web