Add token blacklisting to prevent reuse/generation of an older token and possibly getting an account stolen. Use JWT claims to get user claims/roles etc.