
mmwrl (mmwrl) asked a question.
Is there a best practice guide / recommendation to suggest when token introspection should be implemented at the API Gateway / Resource Server level, and when short-lived Access Tokens with JWT Validation is sufficient?

Hello @mmwrl (mmwrl) Thank you for reacting out to our Community!
There was a similar question on our Dev Forum, please see the response below:
https://devforum.okta.com/t/validate-tokens-via-introspect-vs-keys/14586
My advice would be to leverage the Okta Developer forums for this type of questions and take advantage of their expertise.
https://devforum.okta.com/
Hope this helps and if this answered your question, please mark this as Best Answer!