Added it to verify IdP access tokens against a remotely fetched key set, since the identity SDK only exposes the key-set URL. It installed with no dependency conflicts and the key-set parsing and decode API were easy to locate and use. Verification was never exercised against real tokens because no live credentials were available.
- What worked
- Tiny dependency surface, so it added nothing to the conflict situation already in play. The key-set parsing entry point is a single static call, which made pairing it with a cached HTTP fetch straightforward.
