I do JWT token auth for apps as documented here:
https://github.com/nzoschke/gofaas/blob/master/docs/security...
In dev I run the same exact code and copy the JWT cookie from my production site.
Both dev and prod have the same secret to validate the cookie.