If only the server which signed the JWT can verify it, how does it solve the problem of NOT having single point of failure?