10 Things You Should Know about Tokens. Couple weeks ago we published a short article about cookies vs tokens in the context of single page applications, in particular applied to AngularJs apps. It seems the community is interested in this topic, so we published a second article on token based authentication in realtime frameworks like There is a great interest in this subject so we decided to continue with an article that explores in more detail some of the most common questions around token-based authentication. So here we go... 1. Tokens need to be stored somewhere (local/session storage or cookies) In the context of tokens being used on single page applications, some people have brought up the issue about refreshing the browser, and what happens with the token. If you are wondering "but if I store the token in the cookie I'm back to square one". 2. In the world of cookies, there are different options to control the lifetime of the cookie: Cookies can be destroyed after the browser is closed (session cookies).

