I’m all for replacing as much 3rd party libs with stdlib but it’s hard to look past the storing of the jwt in localStorage. Please don’t do that people. It’s very easily extracted through xss attacks.
A very good friend of mine is high up the management tree at Ocom (parent company of Leaseweb) and told me they wiped the servers 2 weeks after he got arrested because there were no requests from the dutch government to seize the servers. It's standard policy for Leaseweb to wipe servers 2 weeks after the account is closed and my guess is that Mr. Dotcom knew this very well.