Key capabilities
- Fetch bounded public discovery metadata and JWKS with SSRF defenses
- Keep JWT bytes local while verifying supported asymmetric signatures
- Check issuer, audience, nonce, expiry, not-before and authorized party
- Generate cryptographically random PKCE, state and nonce test values
