Using OpenID Connect in production, how to do full security checks

@danschultzer does Assent work for self issued id_tokens Final: OpenID Connect Core 1.0 incorporating errata set 2

We make use of selfissued tokens at did.app so we can be an act as an Identity provider that can’t track every sign in a client makes