Put roles in the JWT, seed them with Identity, and gate endpoints with RequireRole - plus refresh tokens in HttpOnly cookies so the whole flow works from a browser.
Wire ASP.NET Core Identity's built-in API endpoints to an Angular app - login, a bearer token on every request, and an HTTP interceptor that silently refreshes an expired token and retries the failed call.