JWT Security
A JSON Web Token is a compact claims format that can be signed or encrypted. Decoding a JWT is not validation: relying parties must verify its cryptography and relevant claims.
Verifying signed JSON Web Tokens and enforcing their intended audience and issuer.