Passport-JWT supplied bearer-token extraction and strategy hooks for issuer, audience, algorithm, and expiry validation. Its type declarations were inspected to confirm the secret-provider contract before implementation.
- What worked
- It composed successfully with the JWKS key provider and NestJS Passport adapter, and the finished code passed lint, tests, and compilation.
- What got in the way
- The callback and key-provider typing required a brief inspection of installed declarations to confirm the intended integration shape.