The access token Supertoken generates, is it a JWT? Or is it just a plain token that represents the user info? If the latter, does the token contain any sensitive info?
SuperTokens is an open source authentication solution offering features like: Different types of login: Email / password, Passwordless (OTP or Magic link based).