JWKS (RSA) — SAMPLE
SAMPLE JWKS document exposing the Wave G RSA public key for JWT signature verification tests.
{
"keys": [
{
"kty": "RSA",
"use": "sig",
"alg": "RS256",
"kid": "novus-wave-g-rsa",
"n": "wjABbZXvq5P3tlOX3zTLO0eya00jm19hwq5Z7_pQVVX7TgobE1nj20rY75AHtNprELa42OgFMphwdGf7gNp30KscSr-9JfY_Bn_wyxy1imd4fF9EuYTLY8rwzG-wrrqZfQ3y-HhiUIrtLGco28M4tmEwjyd95i6RkejkUnY3nmeephmGqbxQDPP8Mhc-T48cMmudV60H5lyOL80zSufrfx-AUzatUx9Kimpdn0k7cbaEjFe2j8z8yad29mDwPCEEJplyMH1U9AEeHSwv71QrN3RMHV-UwNamprxWNemhncvN3U3qXueULCKzxVxvwYWKKs8HFO7jvxq-W-n8cCKxrQ",
"e": "AQAB"
}
]
}
Specifications
- Kty
- RSA
- Kid
- novus-wave-g-rsa
- Keys
- 1
- Sample Only
- true
Testing contract
Expected to pass- Scenario
- Exercise JWKS (RSA) — SAMPLE in its jwks workflow. SAMPLE JWKS document exposing the Wave G RSA public key for JWT signature verification tests.
- Expected result
- top-level keys are keys; array lengths: keys=1. Declared feature checks: kty=RSA; kid=novus-wave-g-rsa; keys=1.
What is a .json file?
JSON (JavaScript Object Notation) is a lightweight, text-based data-interchange format representing objects, arrays, strings, numbers, booleans, and null. It is language-independent, human-readable, and the dominant format for web APIs and configuration. It requires a single well-formed root value.
How to use this file
Use an example JSON file to test parsers and serializers, schema validation, Unicode and number-precision handling, and API request or response processing.
How to use this file for testing
“JWKS (RSA) — SAMPLE” is a deterministic Novus Examples fixture for JWT / JWKS testing. Unsigned and SAMPLE-signed JWT variants plus JWKS documents, published sample material only, for auth parser tests.
Documented properties for this file: JSON · 514 bytes. Compare results against paired or grouped companions on this page when present (clean↔damaged, searchable↔scanned, or format twins) so scores stay reproducible across runs.
Download the file once, keep the path stable in CI or local scripts, and treat the spec table as the contract: dimensions, seeds, field lists, and roles are intentional. Corrupt or invalid samples are labelled as such, expect parsers to fail loudly rather than silently accept them.
This is published, SAMPLE-only security material, never a real secret. Point certificate, key, or token parsers at it, test PEM/DER decoding and PKCS handling, and confirm your tooling reads the documented fields; any sample password is printed on this page.
These JSON fixtures are synthetic SAMPLE auth or tool-call shapes for harnesses, never production secrets or live tokens. Validate schema fields and alg variants against the documented role.
Code examples
import json
with open("jwks.json") as f:
data = json.load(f)
print(type(data), len(data))Related files
- jsonSAMPLE JWK — EC P-256 Public KeyA single P-256 public JWK. Its x and y are fixed 32-byte base64url values, left-padded when a coordinate happens to be short — the padding rule that libraries stripping leading zeroes get wrong.

- jsonSAMPLE JWK — Ed25519 Private KeyAn OKP-type JWK holding the Ed25519 key pair as raw 32-byte x and d values. OKP is the newest JWK key type and the one older JOSE libraries reject outright.

- jsonSAMPLE JWK — RSA Private KeyThe full RSA private key as a JWK, including the CRT parameters p, q, dp, dq and qi. It is the input for testing JWK-to-PEM conversion, where dropping the CRT values quietly costs a large amount of signing performance.

- jsonSAMPLE JWK — Symmetric oct KeyThe symmetric HMAC secret used by this wave's HS256 tokens, expressed as an oct JWK. The secret is printed in the specs on purpose so a verifier can be wired up without guessing.

- jsonSAMPLE JWKS — Duplicate kidTwo keys of different types published under the same kid — what a botched key rotation leaves behind. A resolver that returns the first match silently verifies against the wrong key type instead of reporting the ambiguity.

- jsonSAMPLE JWKS — Keys Without kidA JWK Set whose keys carry no kid at all, which RFC 7517 permits. Verifiers must then fall back to trying candidates by algorithm, and the ones that index the set by kid alone find nothing.

Generated by generation/security_wave_g.py. Free for any use, no attribution required, license.