that's a major security risk. even the reddit predecessor uses app tokens (though with the death of 3pa idk if such things still work). that's why I want something that only runs on the client side.
tbf there's nothing stopping userscripts from stealing your jwt token in the cookie, which is just as big a security risk, but at least with userscripts you can read the source code.
my plan would be similar to that one in which I store the jwt with the scheduled posts, with the notable difference of the data remaining on the browser storage. i wont even need to see any passwords since the jwt is already in the cookie which the script could read off of.