There is a lot of discussion on the use of OAuth2+JWT tokens to secure microservices style applications with Browser based single page apps. There are well known issues with