A common accident in APIs that receive JWTs is confusing the ability to "decode" a token with the ability to "validate" it.