I have a couple of back-end APIs that can parse JWT and respond with 401 if required. This is the flow that I have in mind.
401