Currently auth.did.verify_jwt only parses did:key / did:pkh URIs. Add signature verification + leeway-aware exp check; update tests.