JWT: to sign the claims with public key or private key, which way to go? I am looking into sign JWT token with secret key (pem).