Finds the key that signs an algorithm a client chose: a pinned key first, then a signer-group key, then the realm's own.
HMAC is not here; its key is the client's secret, which the caller passes itself.
the JWS algorithm
the certificate-header use case, which decides the signer group
the signer: its key and kid
kid
Error when this realm holds no key for the algorithm
Finds the key that signs an algorithm a client chose: a pinned key first, then a signer-group key, then the realm's own.
HMAC is not here; its key is the client's secret, which the caller passes itself.