Verifies a request's attestation and its proof of possession, once per request however many times it is asked.
the request
method (what the client declared, or anything else to accept either proof), clientId and issuer, the audience a PoP must name
method
clientId
issuer
a promise of { ok: true, method, alg, jti, jkt }, or { ok: false, errorCode, ... }
{ ok: true, method, alg, jti, jkt }
{ ok: false, errorCode, ... }
Verifies a request's attestation and its proof of possession, once per request however many times it is asked.