Installed arctic v3 and used its Google provider for the OAuth authorization-code flow with PKCE (state, code verifier, authorization URL, code exchange, ID token decoding). Install was quick, the type definitions were clear enough to write the integration without other docs, and an invalid code exchange came back as a clean error I could turn into a user message. Not tested against real Google credentials.
- What worked
- Small single dependency; the provider's type definitions made the API obvious; helper exports for generating state and code verifiers and decoding ID tokens covered everything needed.
