💬 Commented on "JWTでユーザー認証する": eternal-flame-AD "I think transition to JWT (or any alternative format than random string we agree on) should be done first, because many features in #13865 are contingent upon a rich token format (tokens with structured info that backend can parse).
パスワード認証を要求するすべてのエンドポイントを sudo トークンに置き換える -> this is essentially granular token policy
sudo モード -> this needs ways to identify tokens too, and we have to agree on a format first before all
SSO -> many SSO services require you to store refresh tokens, so we need a rich format too
"
https://github.com/misskey-dev/misskey/issues/15570#issuecomment-2708588094