privateKey (a KeyObject), privateJwk (an ML-KEM or HPKE
key, #82) or secret; allowedAlg, allowedEnc, expectedKid, and
psk for HPKE mode_psk. An HPKE Integrated JWE carries no enc.
Returns {header:any;plaintext:any}
{ header, plaintext }
Throws
Error with a sentence a caller can hand to a client
Decrypts a compact JWE.