Thanks for your question. I’m happy to chat about this and do my best to explain it!
JSON Web Token is an encoding mechanism. The JWT format itself is not the key factor. Rather, the choice of strategy depends on your application topology.
You can read more about Single Page Applications in this article on OAuth 2.0 implicit grant and SPA. There’s currently activity in the standards world to describe the approach in the article and its implementation more thoroughly, and Auth0 will give additional guidance on it as well as the situation develops.
I hope this answers your question — or if you have additional questions, please let us know!