As seen earlier, the JOSE header and JWT Claim Set are not encrypted, but simply JSON strings encoded in base64The Signature part is used to verify whether the JOSE header and JWT Claim Set have been tampered with