This is a heavily interactive web application, and JavaScript is required. Simple HTML interfaces are possible, but that is not what this is.
Post
Omid Farhang
omid.dev
did:plc:njotjjrqah3zuoja2g56ixts
“Just add JWT” to localStorage ships. It demos well. And it trains teams to treat the browser as a safe vault.
If JS can read your access token, so can XSS.
OIDC + BFF / reverse proxy, short-lived server-side tokens, HttpOnly cookies:
g.omid.dev/R3Guo03
https://g.omid.dev/R3Guo03
2026-07-31T13:48:46.865Z