something something jwt token for implicit flow OAuth I'd guess.
You would hope they verified the signing of the jwt token on the backend, but seems thats too difficult for many dev's.
How is this possible, any examples?
> intents (on Android) and OS pinning in the client configuration of your authorization server.
Can you please elaborate?