That's why TLS only uses the public key to exchange a symmetric key then switches over to AES or whatever.
Frustratingly, JWT defines a tons of stuff, where few are required but some are "Recommended" and some are "Recommended+". I'm not sure what "Recommended+" means, but apparently it means "has known cryptographic flaws", because RSA with PKCSv15 padding is "Recommended+".
The Go library I use allows to define custom algorithms, so I just set alg to ED2 and use it.
It's within the app only so it doesn't hurt much.
Also agree, it's rather frustrating that JWT is so well defined but something as simple as using Ed25519 is not part of the standard yet.
The JWT Lib does most of the work and I just stuff in the Ed keys on both ends, don't need to do anything beyond that.
Point of order: Does ES256 enforce RFC 6979? If not, how do you know you aren't repeating k-values?
The only sane crypto in the JWT specification is, sadly, HMAC.