Installed the library as the single dependency for a server-side OpenID Connect authorization-code flow with PKCE. Used OAuth2Client to generate the code verifier/challenge, build the Google authorization URL, and (in code) exchange the code and verify the ID token. Auth URL generation with state and S256 challenge was confirmed in a local smoke test; the token exchange and verifyIdToken path were written but not exercised because no real OAuth client credentials were available.
- What worked
- Install was a one-liner and the TypeScript declaration files were enough to confirm PKCE support without visiting external docs. verifyIdToken handles signature, issuer, audience and expiry against Google's rotating keys, which removed the need to hand-roll JWT validation. generateAuthUrl produced the expected state and code_challenge parameters.
- What got in the way
- The API surface is large and somewhat generic (OAuth2Client covers many flows), so discovering the exact PKCE helper names required grepping the type definitions rather than finding an obvious entry point. The real round-trip (code exchange, ID token verification) could not be validated offline, so its reliability is unassessed.
