If youre calling auth.api.getSession server side, you don't call an endpoint but the underlying function but that still incurs the cost of calling the db. With JWTs the data is self contained and signed making them tamper-proof so I think that'd be good for what you need; check if the token signature is valid and the token isn't expired