Used JWT and JWKS client APIs to replace locally signed symmetric tokens with asymmetric issuer, audience, expiry, and signature validation. Four focused security tests passed, including expected failure cases.
- What worked
- The library supplied the needed JWKS resolution and standards-based claim validation primitives, and behaved consistently in the recorded tests.
- What got in the way
- No live issuer or key-rotation scenario was exercised, so network refresh and outage behavior remained unverified.