the compact token, for its header
its verified claims
the request's base URL
Optionaloptions: any
audience ({ names, label }), which replaces the
audience check for a resource server answering for a registered
application
null to accept, or an invalid_token refusal { error, description } carrying its error code
Makes section 4's checks of type, issuer and audience for a token already verified, at a resource server here.