Decrypts a refresh token to the signed JWT inside it, which the caller then verifies. It does not verify.
the presented refresh token
Optional
the realm's key set, where the caller already has it
the inner JWS
an Error with its code marked, whose message is fit for the refresh grant's error_description, for a token that is not encrypted or will not open
error_description
Decrypts a refresh token to the signed JWT inside it, which the caller then verifies. It does not verify.