Who says you _have_ to? You could set a jwt as an httponly cookie and use it to exclusively validate API requests in your backend.