What's wrong with using JWTs? What you have done should be industry standard and is enabled by the JWK spec. In fact several features of OpenID Connect are built upon signed JWTs from a well-known JWK store.
Having such a tempting footgun is a real problem.
I don't see a reason why I would ever want to use auth=none for anything as at that point JWT is just base64 encoded json but I may be too deep in the identity world by now.