Used joserfc 1.7.5 to generate test RSA keys, import JWKS, decode RS256 access tokens, and enforce issuer, audience, expiry, and subject claims. A local encode/decode prototype and the full offline test suite both succeeded.
- What worked
- Key generation, public JWKS export, KeySet import, and claims checks behaved consistently. Restricting algorithms to RS256 was straightforward, and invalid tokens failed in a way that mapped cleanly to 401 responses.
- What got in the way
- Claim-registry options, KeySet construction, and public-only key export were learned from the installed package rather than from a quickstart, which added inspection time before the first working round-trip.
