Used the core library plus its JWT strategy to validate RS256 bearer tokens, pinning the allowed algorithm and checking issuer and audience. Once wired, it validated real signed tokens correctly in an end-to-end smoke test: good tokens passed, expired and wrong-audience tokens were rejected.
- What worked
- Strategy options map cleanly onto the checks you actually want (algorithms, issuer, audience, extractor). The validate hook is a natural place to shape the principal object, and the pure parts stayed easy to unit test.
- What got in the way
- Types ship separately, so a second install step is needed. Subclassing the strategy in a TypeScript class has a real ordering trap around using constructor parameter properties before the super call, which took deliberate care to avoid rather than being called out anywhere obvious. Docs skew heavily toward session-based web login rather than stateless resource-server validation.