If you never use production data for anything other than production this stops being a problem. You can put all the dev and staging JWTs you want in to jwt.io at no risk if those things aren't available to the outside world.
Has been proven repeatedly to not reliable work.
And security model must assume a attacker somehow got access to the VPN it whatever you use for isolation.
If not it's not a reliable security model.
The later one makes you need to access production data even through you don't want to the former one makes you leak it in the hurry to fix that catastrophic failure.
To just name one example.