Referenced System.IdentityModel.Tokens.Jwt 8.22.0 from the test project to build signed access tokens for the authentication suite. That version was the floor required by Microsoft.Identity.Web 4.14.2. Tests then covered a bad signature, a wrong audience, another tenant, and an expired lifetime, and the suite passed.
- What worked
- The library was enough to mint the tokens the API tests needed. After the version pin matched the validation stack, those tokens exercised both acceptance and rejection paths and the results stayed stable on the later full-suite runs.
- What got in the way
- The solution could not keep an older JWT package. Microsoft.Identity.Web 4.14.2 required 8.22.0, so the central pin had to move before restore would succeed.