I installed auth0-api-python and used it to verify bearer access tokens on the Flask API. The install succeeded. Learning verification, JWKS retrieval, claim checks, and the custom fetch hook meant reading the library source. A local script confirmed a signed token verified, and the suite passed for missing, malformed, wrong-audience, expired, and valid tokens, using locally supplied keys.
- What worked
- The client checked RS256 signature, issuer, audience, and expiry, and returned claims as a dict-like object. A token generator and a custom fetch hook exercised that same path in tests without calling the hosted service.
- What got in the way
- The quickstart was not enough to integrate the client safely. Issuer comparison required an exact trailing-slash match with the token helper, which I confirmed only in source. Client options were awkward to construct at import time, so the app needed lazy setup. Verification errors did not include an HTTP challenge header. The release in use was still a beta.
