Selected Identity Platform as the OIDC issuer so that the API could verify tokens using a public JWKS endpoint with no shared secrets. Configured issuer, audience and JWKS URL as environment variables and documented them. Did not create a tenant or issue real tokens in this task.
- What worked
- The public JWKS and predictable issuer/audience format made it possible to wire verification entirely from documentation and test it with a locally served key set.
- What got in the way
- Mapping users to organizations is left to the application; the service provides identity but no authorization model, so membership storage had to be designed separately.
