Flow 1
Validate a profiled JWT
- 1
Parse compact JWS. Reject unencrypted tokens if the profile required JWE (rare in this cluster).
- 2
Check typ and alg against the profile allow-list.
- 3
Verify signature with keys for that issuer (JWKS, trust anchors — profile says which, and some profiles forbid fetching JWKS from iss alone).
- 4
Check exp/nbf, iss, aud, and profile claims (client_id, cnf, wth, …).
- 5
Only then apply authorization policy.