I installed passport-jwt 4.0.1 to validate bearer access tokens from issuer, audience, and a JWKS secret provider. The package did not include the declaration file I looked for, so types came from a separate package. Those types also disagreed with the JWKS helper. Runtime tests still accepted a valid token and rejected unauthenticated calls.
- What worked
- The strategy options for bearer extraction, allowed algorithms, issuer, and audience were sufficient, and the JWT tests passed after the types were sorted out.
- What got in the way
- Declarations were missing from the package path I expected, and the secret-provider callback type did not line up with the JWKS helper without reading both sides.