Browser Security Headers Pack — SAMPLE
SAMPLE Permissions-Policy / Referrer-Policy / XCTO / XFO header pack.
Filter by category, format, and testing use case. Each file page includes a full spec sheet, preview, and one download button.
SAMPLE Permissions-Policy / Referrer-Policy / XCTO / XFO header pack.
SAMPLE CSP header line for CSP parsers and security-header scanners.
Intentionally misconfigured CORS SAMPLE (* + credentials) for policy linters.
SAMPLE CORS response header block as plain text for header parsers and policy tests.
SAMPLE CRL metadata JSON (no binary CRL) for revocation-list UI and loader tests.
Deterministic SAMPLE Ed25519 private key for SSH/TLS tooling tests.
Password-encrypted SAMPLE PKCS#8 private key (password printed in specs) for decrypt-import tests.
SAMPLE htpasswd using Apache APR1 MD5-style hash for legacy Basic-auth tests.
SAMPLE htpasswd with a bcrypt hash line for Basic-auth file parsers.
Multi-user SAMPLE htpasswd mixing bcrypt, APR1, and {SHA} lines for algorithm-detection tests.
Empty JWKS keys array for edge-case JWKS loaders.
SAMPLE JWKS document exposing the Wave G RSA public key for JWT signature verification tests.
Intentionally invalid JWT (truncated) for parser error-path tests.
SAMPLE HS256 JWT with a past exp claim — for expiry-validation harnesses.
SAMPLE JWT with alg=HS256 for auth parsers and algorithm-handling tests. Published sample material only.
SAMPLE JWT with alg=HS384 for auth parsers and algorithm-handling tests. Published sample material only.
SAMPLE JWT with alg=HS512 for auth parsers and algorithm-handling tests. Published sample material only.
SAMPLE JWT with alg=none for auth parsers and algorithm-handling tests. Published sample material only.
SAMPLE JWT with alg=RS256 for auth parsers and algorithm-handling tests. Published sample material only.
SAMPLE JWT with alg=RS384 for auth parsers and algorithm-handling tests. Published sample material only.
SAMPLE JWT with alg=RS512 for auth parsers and algorithm-handling tests. Published sample material only.
JWT Header Claims — RS256 SAMPLE — unsigned JSON companion for claim-parser tests (not a live token).
JWT Payload — Expired SAMPLE — unsigned JSON companion for claim-parser tests (not a live token).
SAMPLE OAuth device-authorization response for device-flow client tests.
OAuth 2.0 SAMPLE error JSON (insufficient_scope) for client error-path tests.
OAuth 2.0 SAMPLE error JSON (invalid_client) for client error-path tests.
OAuth 2.0 SAMPLE error JSON (invalid_grant) for client error-path tests.
OAuth 2.0 SAMPLE error JSON (invalid_scope) for client error-path tests.
OAuth 2.0 SAMPLE error JSON (temporarily_unavailable) for client error-path tests.
OAuth 2.0 SAMPLE error JSON (unauthorized_client) for client error-path tests.
SAMPLE OAuth error JSON for token-endpoint failure handling.
SAMPLE RFC 7662-style token introspection response for auth middleware tests.
SAMPLE OAuth 2.0 token endpoint JSON with access, refresh, and id_token fields.
SAMPLE OpenID Connect discovery document for OIDC client and metadata parsers.
ASCII-armored SAMPLE-shaped PGP public key placeholder for armor detectors (not a cryptographically valid key).
PKCS#10 certificate signing request SAMPLE for CSR parsers and CA tooling smoke tests.
SAMPLE PKCS#12 keystore (password `novus-sample-wg`) for keystore importer tests. Not byte-stable.
Published SAMPLE RSA-2048 private key (PKCS#8 PEM). Never use for a real identity.
SAMPLE HTTP security header fixture (content-security-policy-report) for scanner regression.
SAMPLE HTTP security header fixture (cross-origin-embedder) for scanner regression.
SAMPLE HTTP security header fixture (cross-origin-opener) for scanner regression.
SAMPLE HTTP security header fixture (cross-origin-resource) for scanner regression.
SAMPLE HTTP security header fixture (expect-ct-legacy) for scanner regression.
SAMPLE HTTP security header fixture (permissions-policy) for scanner regression.
SAMPLE HTTP security header fixture (referrer-policy-strict) for scanner regression.
SAMPLE HTTP security header fixture (strict-transport-security) for scanner regression.
SAMPLE HTTP security header fixture (x-content-type-options) for scanner regression.
SAMPLE HTTP security header fixture (x-frame-options-deny) for scanner regression.
Single-entry SAMPLE authorized_keys file for SSH access-control parsers.
SAMPLE OpenSSH client config stanza for SSH config parsers.
OpenSSH-format SAMPLE Ed25519 public key for authorized_keys and SSH parsers.
SAMPLE SSH known_hosts with fictional hostnames for known_hosts parsers and StrictHostKeyChecking tests.
SAMPLE X-XSS-Protection: 0 header for legacy header scanners.
Same SAMPLE certificate as .crt (PEM bytes) for tools that expect the CRT extension.
DER-encoded twin of the Wave G SAMPLE certificate for binary X.509 decoders.
Self-signed X.509 SAMPLE certificate in PEM under /files/security/ — published sample material for TLS and PEM parsers.
Two-PEM-block SAMPLE chain file for multi-cert parsers and bundle importers.
We use Google Analytics and show ads via Adsterra and Infolinks. Non-essential cookies and ad scripts run only after you allow the matching categories. See our cookie policy.