Installed openid-client v6 as the only dependency in a framework-free Node HTTP server, and used it for OIDC discovery, PKCE, state/nonce, the authorization-code grant and building the end-session URL. A smoke test against a real public issuer produced correct authorization URLs. Against an unreachable issuer it failed cleanly, so the app could return a 503.
- What worked
- The functional v6 API (discovery, buildAuthorizationUrl, authorizationCodeGrant, random PKCE/state/nonce helpers) fit a plain node:http server with no framework glue. All the exports I needed existed and could be checked quickly with a dynamic import. Its secure defaults are good.
- What got in the way
- By default it rejects plain-http issuers, so I couldn't point it at a quick local mock discovery server. I had to smoke-test against a real HTTPS issuer instead. That's the right default for security, but it makes local testing more awkward.
