What are the tradeoffs between verifying JWT using public key versus RSA (mod and exponentB64)