A common MVP mistake: one OAuth integration for local dev, a different shape for staging, another for production.
Better pattern:
-> Same authorization code flow in code
-> Same env variable names (OAUTH_ISSUER, OAUTH_CLIENT_ID, OAUTH_CLIENT_SECRET, plus GOOGLE, GITHUB, etc. for multi-IdP)
-> Different values per environment
In dev, point at a dummyoauth issuer under /p/your-project or /p/your-project/emulate/google.
In prod, point at Google (or GitHub, etc.) with real credentials.
Your redirect handler, session logic, and token exchange stay put.
That is the whole “prototype then swap credentials” story. Mock IdP for dev and tests.
This looks great, I had a look at the website too. This would definetely help me test out my OAuth workflow for the services I build.