* respect cache control for auth.jwt * add documentation * add small note on cache control header ignores * make distinction of env