don't use JWT. JWT terrifies me, and it terrifies all the crypto engineers I know. As a security standard, it is a series of own-goals foreseeable even 10 years ago based on the history of crypto standard vulnerabilities. Almost every application I've seen that uses JWT would be better off with simple bearer tokens.
Also, link to a longer comment from him about why JWT is a bad plan.
Also, link to a longer comment from him about why JWT is a bad plan.