That said, the documentation does this thing I see a lot where the author focuses entirely on things that are good. It repeats and clarifies things that are good (you can reduce the scopes of offline, but never increase the scope of tokens, and you can do it offline, without contacting servers. Any server can validate credentials because it uses public keys. And did we tell you about attenuating tokens?), but it kind of sweeps anything that is NOT a discriminator under a rug a bit. I don't think it's malicious. Creators get excited about the exciting bits of their project.
But there are a lot of details that may or may not be present, and if I'm evaluating your thing, I want to know which exist an which don't. Given a long-term token, can I create short-term, auto-expiring tokens? Is there some revocation mechanism? How do these things line up against JWT or OAuth? When should I prefer this, but also when should I NOT prefer this?
Still, I like a lot about the documentation. I love how it's not afraid to get into the weeds about EXACTLY what it does without losing the clarity. It's really easy to follow when it gets technical, which is rare.