I am using spring security, and I created a JWT checker. It checks only expiration time so far.
The problem is I expose two different apis, and the callers are also using