Used token creation and OpenID configuration stubbing to validate locally minted tokens without external metadata. Worked reliably after aligning signing keys, issuer, audience, and scope claims.
- What worked
- Local token minting plus static configuration removed network dependence from the test suite.
- What got in the way
- Correct combination of validation settings and required claims was not obvious from errors alone.