I installed passport-jwt 4.0.1 and used its JWT strategy to read the bearer header, load a signing key from a callback, and accept only RS256 tokens with the expected issuer, audience, and expiry. The secret-provider callback shape was clear only after reading the installed strategy option types.
- What worked
- After the callback types lined up, the strategy rejected bad tokens and accepted a signed token in unit tests and against the built server.
- What got in the way
- The secret-provider types were not obvious from the package surface, so the installed declarations had to be opened before the strategy matched the JWKS helper.