> Unless you've used cookies with the HttpOnly flag XSS trivially escalates to session stealing
Then again you could just use CSP and mitigate almost 100% of those XSS cases. Yes, even most of the stored ones. And with JWT + JavaScript you don't have to worry about all the oddities in the way cookies work, which is a huge plus.