Used the library, already transitive through the resource-server starter, to sign identity-provider-shaped tokens with an RSA key generated at start-up. The claims-set builder, JWS header builder and RSA signer were straightforward to compose. Not compiled or run here.
- What worked
- Fluent builders for claims and headers made producing realistic tokens short and readable, and no new dependency was needed.