Consider mentioning this in Mobile App Authentication Architectures or create a new BEST regarding JWTs https://auth0.com/blog/protect-your-access-tokens-with-dpop/