Only allow one device at a time

JWT token need to expire after a new device with the phone number is registered. how to implement this?

You can leverage a rule and modify your token after a specific successful login event has occurred. To read more about rules I have linked the documentation below.

