{ token, type, base, issuer, clientId, clientSecret, request }: the token as presented, its declared type, this realm's
base URL and issuer, the exchanging client, its secret (for a JWT
encrypted to it) and the request (so it is spent only if tokens are
issued)
a promise of { ok, format, issuer, subject, claims, audience, forwarded, relyingParty, id, issuerKind, application } or { ok: false, errorCode, error, description }
Verifies one assertion presented to the token exchange.