The expected shape of the claims payload.
The serialized compact JWT (header.payload.signature).
The shared symmetric key matching the one used to sign the token.
Validation constraints for issuer and audience.
A Promise resolving to the typed claims payload.
Verifies a compact JWT's HMAC signature, expiration, and claim constraints.
Enforces strict algorithm validation to prevent algorithm confusion attacks (such as rejecting the unsigned
nonealgorithm).