I inspected the JWT library already present in the project environment and used it to round-trip RS256 tokens against a JWKS document. It could require audience, issuer, and expiry, and the verification tests built on it passed. Safe defaults were not obvious, and signature errors did not distinguish a missing key id from a wrong key.
- What worked
- Decode accepted a JWKS set directly. The decode docstring documented options to require audience, issuer, and expiry. Local RSA round-trips behaved consistently, which was enough to lock the verifier and get the suite passing.
- What got in the way
- Audience, issuer, and expiry are enforced only when those claims are present unless require flags are set, so a token missing them can be accepted if that docstring is missed. An unknown key id and a mismatched key both failed as a bad signature, so rotation handling needed an extra refresh policy rather than a distinct error.