Used its Passport helper to resolve signing keys from the tenant JWKS URL with caching and rate limiting enabled. In tests the helper was stubbed to return a locally generated public key so nothing touched the network; in the unmocked smoke run an unreachable JWKS host correctly degraded to 401 instead of a server error.
- What worked
- The Passport-specific helper made wiring a one-liner, and cache and rate-limit options are sensible defaults to turn on.
- What got in the way
- Testing requires module-level mocking since the helper performs its own HTTP fetch; there is no obvious injection point for a static key set.
