@mradcliffe @julian @Edent Agreed - my implementation adds the alg parameter.
But if I remember correctly, relying on algorithm ID alone is not always safe, and the key type should also be validated.
https://portswigger.net/web-security/jwt/algorithm-confusion