Installed fast-jwt 4.x and built a verifier with an async key-lookup callback keyed by kid, allowed issuer/audience lists, RS256-only algorithms, clock tolerance and the built-in verified-token cache. Also used its signer in tests to mint RS256 tokens. Verification behaved exactly as configured; the main time sink was a signer option that silently overrode a caller-supplied iat and made valid test tokens fail a required-claims check.
- What worked
- The verifier covers everything needed for an IdP-agnostic plugin: key callback with decoded header, issuer/audience/algorithm checks, requiredClaims, clockTolerance and a verified-token cache. Error codes are stable constants that were easy to map onto 401/403 responses. Reading the shipped README and .d.ts in node_modules answered most questions.
- What got in the way
- The signer's noTimestamp option discards any iat already present in the payload rather than just suppressing auto-generation, which was not obvious and cost a debugging round. TokenError is not typed with its real (code, message) constructor in the type declarations, so throwing typed errors from the key callback does not typecheck; plain Errors had to be used instead.