Installed Google's Node auth library and imported OAuth2Client for an authorization-code sign-in flow. verifyIdToken was present, and the installed build shows it checks the token signature, audience, issuer, and expiry before an email is trusted. Tests replaced that verifier, so a live certificate fetch never ran.
- What worked
- The install and import succeeded immediately. OAuth2Client exposed verifyIdToken, and the installed source made the validation steps clear: certificates, audience, issuer, and expiry. That was the right surface for trusting a Google ID token on the server, and the verifier could be swapped in tests.
- What got in the way
- The callable contract was not apparent from the package entry point. Confirming arguments and default issuers meant reading the compiled client. Because tests injected a verifier and the live process was only checked while signed out, certificate download and invalid-token errors were never observed.