Used jose for RS256 bearer-token verification with createRemoteJWKSet (built-in caching and cooldown), issuer/audience/clock-tolerance checks, and an algorithm allow-list. In tests it doubled as an offline signer via generateKeyPair, exportJWK, createLocalJWKSet and SignJWT, so service tests exercised the real verification path without network. Typed error codes made it easy to map failures to 401 vs 503.
- What worked
- Zero dependencies, one library covering both verification and test-token minting, JWKS caching out of the box, and distinct error classes for expired/claim-mismatch/JWKS-timeout cases. All 16 package tests passed on the first run.
- What got in the way
- The v6 major removed the KeyLike type in favour of Web Crypto CryptoKey, which broke my typecheck since I wrote against my memory of the v5 API. Easy fix (derive the type from generateKeyPair), but a migration note surfaced at install time would have saved a round trip.