This does a better job that I'm going to try for in a HN comment: http://cryto.net/~joepie91/blog/2016/06/13/stop-using-jwt-fo...