To logout the token just invalidate or change the `jwt_id`
You might set the jwt to expire in 15 minutes, for a 5-10 minute session allowing for clock drift - and just eschew the black list.
But now you need a longer lived "refresh token" and a service endpoint that handles that, along with a black list.
It is "simpler" in the sense that: your app have two separate auth/clients - one is very simple - gets a jwt token and renews every ten minutes - the rest of your app simply uses the jwt.
On your server side, you can have a dedicated/simple service that only renews jwts given a refresh token (checks refresh token blacklist) - and your other apps blindly trusts the jwt (checks signature and the short timestamp).
You've now reimplented half of kerberos - along with "pass the hash" - and at least you can reason about the trade-offs you've made...