Installed 3.8.8 and used it for PKCE, state, nonce, discovery, and ID-token claim checks. Searches inside the package did not surface the exports, so the readme, types, and build output had to be read directly. The token-response helper checks issuer, audience, expiry, nonce, and subject, but it does not verify the ID token signature unless a separate call is added. A running app produced an authorize redirect with PKCE and no client secret. The token endpoint was never called with a live client.
- What worked
- Authorization helpers emitted PKCE, state, and nonce without putting the client secret on the redirect. Issuer comparison, the required iss response parameter, and client-secret POST authentication were all available once found in the source. The project typecheck passed against the package types.
- What got in the way
- The default authorization-code response helper does not verify the ID token JWS signature, which is easy to miss from the helper names alone. Client authentication and the extra signature check were only clear after reading the implementation.