Validating SPA JWT Tokens in the backend

PS:

Omitted to mention the audience when requesting the token.