Spring Boot SSO是否基于JWT?是否在服务器内存中维持会话?
Great questions—let’s unpack these two points clearly, since Spring Boot SSO has flexible options depending on how you configure it.
1. Is Spring Boot SSO based on JWT?
Short answer: No, it’s not mandatory. Spring Boot SSO is a broad concept built on Spring Security’s ecosystem, which supports multiple token formats and authentication mechanisms.
JWT is a super popular choice for SSO in Spring Boot because it’s stateless and self-contained (all user claims are encoded directly in the token), but it’s far from the only option. You could also use opaque tokens (tokens that don’t carry user data directly—your server has to validate them against a dedicated store) or even session-based SSO (using Spring Session to share sessions across services, for example).
For context: If you use spring-security-oauth2-resource-server with JWT-specific configuration, you’re leaning into JWT-based SSO. But if you set up a traditional OAuth2 authorization server with in-memory/database token storage, you’re working with opaque tokens instead.
2. Does it use JWT or keep sessions open in server memory?
This entirely depends on your implementation choice:
- JWT-based SSO: This is stateless by design. The server doesn’t store any session data in memory (or anywhere else) because all necessary user information lives inside the JWT. When a client sends the token, the server just verifies its signature and extracts the claims—no session lookup required.
- Session-based/Opaque Token SSO: If you go this route, the server does maintain state. Examples include:
- Traditional OAuth2 setups, where the authorization server stores access tokens in memory, a database, or a cache like Redis. The server checks this store to validate tokens when clients present them.
- Session-based SSO using Spring Session, where sessions are stored (in memory, Redis, etc.) and shared across your Spring Boot services. Clients use session cookies to authenticate, and the server looks up the session state on every request.
In most modern, distributed Spring Boot apps, JWT is preferred for its scalability (no server-side session storage), but session-based SSO is still common for simpler, monolithic setups.
内容的提问来源于stack exchange,提问作者DavidSoles

