Notes and write-ups, mostly on web application security.
A signature that verifies is not the same as a token you should accept. Algorithm, audience, and the difference between decode and verify.