Skip to main content

JWT Session Management and Token Rotation for Private Organizations

I am experiencing a critical issue where the JWT provided during SDK initialization appears to be permanently bound to the session.

This causes 401 Unauthorized errors when the JWT expires, even if I attempt to update it mid-session.

This limitation makes the Feedback widget unusable with expiring JWTs when using Private Organizations and JWT-based SSO.

I would like the SDK to introduce functionality to allow JWT rotation at runtime (e.g., `Featurebase('setToken', '<new-token>')) or to renew the session without requiring a full SDK reinitialization.

My goal is to securely use Private Organizations and JWT-based SSO with an expiring JWT.

Post type
💡 New feature
What part?
Widget
Status: Completed7 comments

Log in to comment and vote

Comments7

  • Bruno H changed status to Planned
    Team•

    Aug 6, 2025

    Pinned

    Hey Jared,

    Thanks for bringing this to our attention.

    Currently, our JWTs and user sessions don't really have an expiration, so sessions should never get lost like you are describing - most likely, is an implementation issue.

    We're planning to introduce support for expiring tokens in the future. I'll be sure to update this post as we make progress on it.

    You can also use the SDK auto-authentication & data sync setup for the feedback widget in a private org if you provide the userHash to it.

  • Seline Moon

    •

    Apr 20

    Vercel was compromised and they recommended to rotate env variables that were stored as plaintext. https://vercel.com/kb/bulletin/vercel-april-2026-security-incident

    Storing as plaintext is my mistake though. But now I’m in the process of rotating env variables, and with Featurebase it doesn’t seems possible to rotate the automatically generated JWT token.

    • Robi Rohumaa

      Team•

      Apr 21

      Hey!
      Please reach out to us via the live chat. We can help rotate the key there.

      • Seline Moon

        •

        Apr 21

        Hi! I tried to talk to a human via the chat, but the bot tells me I can't because I'm a free user.

        I opened up a ticket though, if that helps: #117762

        • Robi Rohumaa

          Team•

          Apr 21

          Yep, replied to you in the ticket.

    • Robi Rohumaa

      Team•

      Apr 21

      Pinned

      For others: Token rotation is now rolled out. You can rotate your key from Dashboard → Settings → Access & Security → Rotate Secret

  • Jared Scheib

    •

    Aug 6, 2025

    I posted a bunch of comments that provide additional context at

    https://feedback.featurebase.app/p/jwt-auth-for-feedback-and-bug-report-widget.