Verify HMAC integrity before claim-policy review
Inspect the alg and claims, verify the unchanged compact signature with the exact shared secret, then enforce application-specific issuer and audience policy.
- Decode and inspect alg
- Obtain the secret through an approved channel
- Verify HMAC and time status
- Check issuer and audience in the service
- Discard diagnostic secrets safely