Currently, my application will hand out a JWT access token when the user logs in with an expiration time of a few minutes. Each request the user makes to the server (as long as