You can split the JWT to have parts stored in cookie and another in localstorage. Stich the two together on the server.