If they have all the JWTs, seeing if one had a different e-mail than the logged-in user should be fairly doable.
If they have all the JWTs, seeing if one had a different e-mail than the logged-in user should be fairly doable.