The documentation for webhooks says that the webhook request will be secured with bearer auth
https://developer.atlassian.com/cloud/jira/platform/webhooks/#webhooks-authentication-for-oauth-2-0-apps
After I decode the token using my client secret, what should the body of the decoded token contain?
Edit for clarity: The payload of a JWT contains a number of "claims". These can be things like iss (issuer), exp (expiration time), sub (subject), aud (audience), and others. I'm wondering what claims will be included in the JWT that Jira passes to my webhook callback. For example, can I expect the expiration time to be included, so that I can verify the token hasn't expired?