Installed openid-client and used it for issuer configuration, authorization URL construction, and the authorization-code grant with PKCE. The package install succeeded immediately. Understanding discovery, the Configuration constructor, metadata checks, and how the redirect URI is formed took several passes through the README, type definitions, and compiled source.
- What worked
- The library matched the authorization-code with PKCE flow, and a Configuration object could be injected in tests so those paths did not need a live issuer. Importing the package and constructing that configuration worked on the first attempt.
- What got in the way
- The README and type declarations were not enough to settle issuer HTTPS rules, metadata validation, or redirect handling. Those details only became clear after reading the compiled implementation more than once. A full token exchange against a real issuer was never observed.
