Ah, I've played around with that too... with a properly decoded JWT, you could theoretically just call req.login and log in the user.
But that's implciitly trusting the token itself, so if your secret ever got out, then all accounts are essentially compromised 😦