When validating a JWT, what are some of the claims that you must confirm? (Select all that apply.) A. The exp (expiration) has not passed. B. The algorithm is sufficient. C. The signature matches the payload. D. The token was Base64 encoded. E. The iss (issuer) is the auth server you expect. F. There is a refresh token. G. The cid (client ID) is the client you expect. H. The token was encrypted.