If JWT is too complicated and confusing, OpenID Connect inherits all that complexity and then adds some more.
The authentication event is a regular JSON object.
There is no need to validate it since it was received from a server-to-server TLS-protected HTTPS request.
This is not anywhere near as complicated as using JWT for session storage directly.
But if you go as far as not verifying the ID Token for, what do you need OpenID Connect for? Just use plain old OAuth 2.0.
* The Discovery URL
* Standardisation in the subject name
* The userinfo endpoint