Used its passport secret-provider helper to resolve signing keys from a JWKS endpoint with caching and rate limiting enabled. I verified the export shape before wiring it, then drove it against a local JWKS server with a real keypair: correct keys resolved, tampered signatures and wrong-issuer tokens were rejected.
- What worked
- The passport-oriented helper drops straight into the strategy's secret slot, so there is no custom key-fetching code. Caching and rate-limit options are first-class rather than something you bolt on. Behaved correctly against a hand-rolled JWKS document, which suggests a faithful spec implementation.