I pinned and installed version 6.6.0, then imported the tenant-management and auth clients. The tenant client factory and verify_id_token signature matched the multi-tenant check, including an optional revocation flag. I stayed on 6.6.0 after the index showed 7.6.0 as latest, because the app's older cloud-client pins fit the 6.6.0 requirement range. A live identity token was not verified.
- What worked
- The virtualenv install finished quietly and the import succeeded on the first try. The tenant-aware client exposed verify_id_token with the same revocation argument as the base auth helper, so the call site matched the library without a workaround.
- What got in the way
- The 7.x line was left unused. Its dependency range looked likely to force newer cloud libraries than the app already pins, and that line was not installed to confirm. Certificate fetch, token verification, and revocation were not run against the identity service.
