Replaced python-jose with PyJWT (crypto extra) to verify RS256 workspace tokens from a JWKS URL or PEM, enforce required claims, issuer, audience, leeway, and keep a transitional HS256 path. Tests covering expiry, missing claims, alg confusion, and JWKS outage all passed.
- What worked
- Required-claims, issuer/audience and leeway options mapped directly to the hardening I wanted. PyJWKClient handled JWKS key lookup by kid with a timeout, and its connection error class let me return 503 instead of 401 on outages. It refuses to HMAC-sign with a PEM key, which is a useful guard against algorithm confusion.
- What got in the way
- I had to inspect the installed package to confirm the PyJWKClient constructor arguments and which exception classes exist in this version. Because the library refuses that signing, I had to build the HS256-with-public-key attack token by hand in the tests.