Recommended as the standard token issuer for a container deployment already on AWS, with one regional user pool, federated corporate login, short lived access tokens and scoped resource server. Implemented services to accept its OIDC bearer tokens via cached JWKS without a live pool to test against.
- What worked
- Issuer, audience, scope and expiry model mapped cleanly to stateless verification. Single issuer avoided multi region validation complexity. Separation of user tokens from machine client credentials was clear to implement.
