How do I make sure that the request my EBS is getting, is genuinely them?

Are you sure you’re using the correct secret? You need to use the secret in the Extension Client Configuration section of the extension console, not the Twitch API Client Secret which is separate and is use for the API side of things and wont work for JWT verification/signing.