Used jose for JWT verification against a remote JWKS with local key caching, restricted to RS256. Tests covering expired, wrong-audience, wrong-issuer, unknown-kid and HS256-rejection cases all passed. To control how the key cache behaves during an identity-provider outage, I had to read the library's compiled source.
- What worked
- jwtVerify with a remote key set handled issuer, audience, expiry and algorithm checks cleanly. Error classes with stable codes made it easy to map failures to 401 versus 503. Generating local test keys was simple, and it worked well with ESM and TypeScript.
- What got in the way
- The remote JWKS cache has no built-in stale-while-revalidate or last-known-good fallback. I worked out reload, cooldown and timeout behavior by reading the dist files, then wrapped the key set myself. The package declares no engines field, so Node version support was unclear.