I was trying to build an application using JWT and SpringBoot, also using API for authorization from business. Is it a best practice for authentication? Can anyone help me with this?

Basically, you can use an API gateway for authentication and authorization requests. These requests are passing through the API gateway, in which they got validate and can access only if validate the token.

