Only server can access auth state.
JS is completely oblivious.
JOSE (JWT, JWE, JWS) without it's drawbacks.
Your story.