JWT Session Management and Token Rotation for Private Organizations
I am experiencing a critical issue where the JWT provided during SDK initialization appears to be permanently bound to the session.
This causes 401 Unauthorized errors when the JWT expires, even if I attempt to update it mid-session.
This limitation makes the Feedback widget unusable with expiring JWTs when using Private Organizations and JWT-based SSO.
I would like the SDK to introduce functionality to allow JWT rotation at runtime (e.g., `Featurebase('setToken', '<new-token>')) or to renew the session without requiring a full SDK reinitialization.
My goal is to securely use Private Organizations and JWT-based SSO with an expiring JWT.
- Post type
- 💡 New feature
- What part?
- Widget
Log in to comment and vote
Comments7
Aug 6, 2025
PinnedHey Jared,
Thanks for bringing this to our attention.
Currently, our JWTs and user sessions don't really have an expiration, so sessions should never get lost like you are describing - most likely, is an implementation issue.
We're planning to introduce support for expiring tokens in the future. I'll be sure to update this post as we make progress on it.
You can also use the SDK auto-authentication & data sync setup for the feedback widget in a private org if you provide the userHash to it.
Seline Moon
Apr 20
Vercel was compromised and they recommended to rotate env variables that were stored as plaintext. https://vercel.com/kb/bulletin/vercel-april-2026-security-incident
Storing as plaintext is my mistake though. But now I’m in the process of rotating env variables, and with Featurebase it doesn’t seems possible to rotate the automatically generated JWT token.
Robi Rohumaa
Apr 21
Hey!
Please reach out to us via the live chat. We can help rotate the key there.
Seline Moon
Apr 21
Hi! I tried to talk to a human via the chat, but the bot tells me I can't because I'm a free user.
I opened up a ticket though, if that helps: #117762
Robi Rohumaa
Apr 21
Yep, replied to you in the ticket.
Robi Rohumaa
Apr 21
PinnedFor others: Token rotation is now rolled out. You can rotate your key from Dashboard → Settings → Access & Security → Rotate Secret
Jared Scheib
Aug 6, 2025
I posted a bunch of comments that provide additional context at
https://feedback.featurebase.app/p/jwt-auth-for-feedback-and-bug-report-widget.