Used PyJWT to replace HS256 HMAC tokens with RS256 verification via PyJWKClient and jwt.decode (audience and issuer). Confirmed the JWKS helper is exported from the jwt package. Local tests mocked JWKS and signed with an RSA key; a first mock passed the private key into verify and failed, then passed after switching to the public key.
- What worked
- PyJWKClient plus decode with algorithm, audience, and issuer checks was enough for Auth0-style access tokens. JWKS-client errors subclass the same JWT error type, so one handler covered fetch and decode failures. After the key object was a public key, valid tokens decoded and the HS256 negative case failed as expected.
- What got in the way
- jwt.decode with a private RSA key object raised AttributeError from the cryptography key instead of a clear public-key requirement. That error is not a JWT base error, so it had to be caught separately. TestClient was not involved; this was isolated decode testing.