Used jose to verify access tokens against a remote JWKS in a guard, and in tests to generate key pairs, build a local JWKS and sign tokens. One dependency covered both runtime verification and test token minting, and all auth tests passed.
- What worked
- No transitive dependencies. Remote JWKS fetching and caching is built in. The local JWKS and signing helpers made it easy to test without a live identity provider. Issuer, audience and expiry checks are simple options.
- What got in the way
- The latest major version is ESM-only, so I had to pin the 5.x line for a CommonJS build. A key type name in my tests didn't match the 5.x typings and needed a quick swap, and the return type of the remote JWKS helper took some care to annotate.