I installed jwks-rsa 3.2.0 and used its Passport helper to resolve RS256 signing keys, with caching and rate limiting enabled. The published secret-callback type did not match passport-jwt's provider callback, so I read the integration source to confirm the runtime shape was compatible. The project then typechecked, tested, and built.
- What worked
- The Passport helper, client, and request code were readable enough to confirm callback arity, key id handling, and that an absolute JWKS URL avoids relative resolution. Token tests passed after that.
- What got in the way
- The TypeScript types look aligned with a different JWT middleware than passport-jwt, so the definitions disagreed with the runtime helper and forced a source-reading detour before the build was trustworthy.