The line I wish more teams internalized: decoding a token tells you what it claims, only verifying the signature tells you who actually said it. The same gap shows up in audit logs and signed receipts, where people read the payload and skip the check. Do you pin the expected algorithm on the verifier side, or trust the alg field in the header?
iin1005h22