// the find
appleboy/gin-jwt
JWT Middleware for Gin framework
A JWT auth middleware for Gin that handles login, refresh, and logout, with access tokens as JWTs and refresh tokens as separate opaque RFC 6749 tokens stored server-side. Useful if you want Gin-native auth without wiring up golang-jwt by hand and want refresh token rotation done correctly instead of just reusing JWTs for everything.
Separating access tokens (JWT) from refresh tokens (opaque, server-side, rotated on use) is the right call and most hand-rolled JWT middleware gets this wrong by just minting a longer-lived JWT as the 'refresh token.' Pluggable refresh token storage (in-memory default, Redis with client-side caching) means you're not locked into one backend. CI is solid for a middleware repo: tests, Trivy scanning, CodeQL, and a codecov badge that's actually wired up, not just decorative.
The multi-provider JWKS/Azure AD support advertised in the README is mostly commented-out pseudocode you're expected to implement yourself (key fetching, caching, rotation) — it's a KeyFunc hook, not a shipped feature, despite reading like one. In-memory refresh token storage won't survive a restart or work across multiple instances, so anyone running more than one replica needs Redis from day one, and that's easy to miss until tokens start failing to rotate in production. The README is bloated with checklists and emoji section headers that pad out the actual API surface, which is small and could be documented in a fifth of the space.