> If the user needs to be loggedin somewhere, they must be online
I will be using JWTs, with asymmetric signatures. An internet connection will only be needed while adding the device for 2FA. The JWT will be generated from the private key already on the phone so internet is not necessary.