Phoenix.Token max_age vs Guardian JWT for expiring, least-privilege credentials
Credential Expiry and Scoping A design requirement for a Phoenix API involves issuing credentials that adhere to least-privilege principles (e.g., separating api:read and api:write scopes) and expire automatically to limit the window of exposure. Two documented paths exist. Phoenix.Token allows signing a payload and verifying it with a :max_age option, provi