JWT is a very bad protocol, it contains an enormous safety hole right in the middle of the design and absolutely every implementation ever has tripped over it

