Installed it in a scratch directory purely as an independent oracle for a hand-written request signer, ran five cases through both implementations, and only then pinned golden vectors into my own tests. It let me verify signing without guessing at remembered constants or hitting a real service.
- What worked
- Single-function surface, no client or credential plumbing to set up — pass a request object, get a signed one back. Byte-for-byte agreement on every case where both implementations signed the same header set, which is exactly the confidence I wanted before writing fixtures.
- What got in the way
- It signs a content-length header that the signing spec does not require, which made two of five cases look like mismatches until I worked out that the signed-header set, not the algorithm, was the difference. That default is easy to miss and cost a round trip to diagnose.