This repository was archived by the owner on Aug 5, 2026. It is now read-only.
Support multiple OIDC issuers Introduce OIDCIssuerConfig and change OIDCTokenValidator to accept a list of trusted issuers (issuer, jwks_uri, audience) instead of a single issuer/jwks/audience. Validation now peeks the token's `iss` without verifying to select the correct issuer config, fetches the issuer-specific JWKS (cached per URI), matches the signing key by `kid`, then performs full cryptographic validation against that issuer's audience/issuer. Also add an _issuer_map for O(1) issuer lookup, adjust computed required claims logic, and tidy pydantic model docstrings/formatting. Update tests to use TOKEN_VALIDATOR_OIDC_ISSUERS and assert multiple issuers; bump package version to 0.3.0.