Building Genuinely Ephemeral Sessions with Auth0 Actions and Next.js
Auth0's Manage Sessions with Actions APIs let a Post-Login Action set a non-persistent cookie mode and short expiry on the Authorization Server's own session. Getting a genuinely ephemeral login end-to-end took matching that on the app's own session too, and an access token that turned out not to be a JWT.