Why do you need a db call for api request when you can just cache session data?
JWT has its own slew of problems, most of them are temporal (eg invalidation of all sessions), usability (eg short expiry), or additional security vectors (many poor JWT implementations, accidentally authenticating invalid tokens w/o signing, careless storage of readable values)
You could build a session cache, either in memory or out of process, but it would still be more work than the token approach