I’m implementing Google login in a Go script and I’m stuck trying to verify the ID Token has been signed by Google.
Specifically I’m trying to do the first bullet point in here.
I’ve obtained the token and split it into its header, payload and signature. But I don’t know how to use Google’s public key to verify the signature.
I saw that generating signature involves a HMACSHA256 algorithm, but I don’t quite know what to do with the JWK or PEM keys that Google provides. I’m currently doing it manually due to certain restrictions.
Does anyone know how I can verify the signature please?