Prevent CSRF and XSS with JWT 2. Use include a CSRF token in your JWT and use local storage to store a CSRF id.
Payload of JWT: { "sub": "1234567890", "name": "John Doe", "iat": 1516239022, “CSRFID”: “k908f-1209-k3809” }
When a JWT is sent in a cookie: localStorage.setItem(“CSRFID”, “k908f-1209-k3809”) When evaluating a request: localStorage.getItem(“CSRFID”) === JWT.CSRF