I vendored the public Python Dynamic Key sources and used them to sign chat user tokens and video channel tokens in the session flow. The packer and access-token modules downloaded on the first attempt. Privilege expiry is stored as the integer passed in, which is easy to misread as an absolute timestamp. Signed tokens were not checked by a live project.
- What worked
- The Python builder sources were small, public, and direct to vendor. Chat and video privilege helpers were enough to mint short-lived tokens locally, and the application suite completed after the modules were added.
- What got in the way
- Expiry is kept exactly as supplied, as a relative number of seconds in the official builder. Treating it as a unix timestamp is an easy mistake, and the samples need a careful read to avoid it. No signed token was presented to the live service.
