The code in your decode function appears to be written for Joken 1.x - Joken.token exists there.
The documentation now warns against using peek_* functions in most cases, as they don’t validate the signature. OTOH, the Google docs for OpenID Connect suggest it may not be a hard requirement.


















