Biggest complaints about JWT is the inability to sign out a user. You can, yes, delete the cookie on the client side, but if the JWT is stolen you can’t be sure that it won’t be used again ( invalidate ).
Same happens on reset password, where by the book you need to sign out the user from every device. Good luck with that having standard JWT implementation.