Skip to content
Novus Examples
json151 B

SAMPLE JWK — Symmetric oct Key

The symmetric HMAC secret used by this wave's HS256 tokens, expressed as an oct JWK. The secret is printed in the specs on purpose so a verifier can be wired up without guessing.

Preview — first 8 linesjson
{
  "kty": "oct",
  "use": "sig",
  "alg": "HS256",
  "kid": "novus-p7-hmac-2026",
  "k": "bm92dXMtcDctc2FtcGxlLWhtYWMtc2VjcmV0LW5vdC1hLXJlYWwta2V5"
}

Specifications

Kty
oct
Alg
HS256
Secret Bytes
42
Secret
novus-p7-sample-hmac-secret-not-a-real-key
Warning
published sample secret — never use for a real identity
Sample Only
true
Seed
70117

Testing contract

Reference control
Scenario
Load the oct JWK and verify the p7 HS256 token with it.
Expected result
The base64url k value decodes to the published secret and the HS256 signature verifies.

What is a .json file?

JSON (JavaScript Object Notation) is a lightweight, text-based data-interchange format representing objects, arrays, strings, numbers, booleans, and null. It is language-independent, human-readable, and the dominant format for web APIs and configuration. It requires a single well-formed root value.

How to use this file

Use an example JSON file to test parsers and serializers, schema validation, Unicode and number-precision handling, and API request or response processing.

How to use this file for testing

“SAMPLE JWK — Symmetric oct Key” is a deterministic Novus Examples fixture for JWT / JWKS testing. Unsigned and SAMPLE-signed JWT variants plus JWKS documents — published sample material only, for auth parser tests.

Documented properties for this file: seed 70117. Compare results against paired or grouped companions on this page when present (clean↔damaged, searchable↔scanned, or format twins) so scores stay reproducible across runs.

Download the file once, keep the path stable in CI or local scripts, and treat the spec table as the contract: dimensions, seeds, field lists, and roles are intentional. Corrupt or invalid samples are labelled as such — expect parsers to fail loudly rather than silently accept them.

This is published, SAMPLE-only security material — never a real secret. Point certificate, key, or token parsers at it, test PEM/DER decoding and PKCS handling, and confirm your tooling reads the documented fields; any sample password is printed on this page.

These JSON fixtures are synthetic SAMPLE auth or tool-call shapes for harnesses — never production secrets or live tokens. Validate schema fields and alg variants against the documented role.

Code examples

import json

with open("jwk-oct-hmac.json") as f:
    data = json.load(f)
print(type(data), len(data))

Generated by generation/security_p7.py. Free for any use, no attribution required — license.