* add keyStore and switch all secret usage to this store - implement static ks - add shared secret * lint: shadow in jwt and missing comment * rename static key group to shared and use top-level shared secret * move siteID extraction (from token) to internal func * lint: merge var and assign for key test