So what's exactly the use case for this? I'm not entirely sure.
Let's say I deploy it. Users of whatever service I provide use this to login to Google, Twitter, etc, then what? do I need to also implement something on the servers I'm protecting behind a login? I.e. some "verification" method that checks whether the client's JWT tokens are valid so I can grant them access?