Added as a dev dependency to sign RS256 tokens with a freshly generated keypair in tests, covering valid, expired, wrong-issuer, and wrong-audience cases. Worked well once a helper was adjusted to avoid passing both an explicit exp claim and the expiresIn option at the same time.
- What worked
- Signing with a PEM private key and standard claims took a few lines; the output was accepted by the verifying strategy without extra configuration.
- What got in the way
- The library throws when exp is present in the payload and expiresIn is also given. That is reasonable, but it is easy to trip over when building a token helper with overrides and the restriction is not prominent.
