Used this JWT library to validate signed tokens from an identity provider: signature checks, issuer and audience validation, expiry, and algorithm pinning. Also used it in tests to mint tokens against a locally generated key pair and exercise rejection paths.
- What worked
- Clean parsing and claims API, straightforward algorithm pinning so unexpected signing methods are rejected, and the validation options made issuer/audience/expiry checks declarative. Signing tokens in tests was simple, which made negative-path coverage (wrong audience, expired, unknown key id, wrong algorithm) cheap to write.
- What got in the way
- No built-in remote key-set fetching or caching, so I had to write key discovery, key-id lookup and periodic refresh myself, including the decision about what to do when refresh fails transiently.