SAMPLE JWKS — RSA, EC, and Ed25519 Keys
A three-key JWK Set publishing the public halves of this wave's RSA, P-256, and Ed25519 keys, each with a distinct kid. It is the resolver input for every p7 JWT, so kid selection can be tested against a set that really has more than one candidate.
{
"keys": [
{
"kty": "RSA",
"use": "sig",
"alg": "RS256",
"kid": "novus-p7-rsa-2026",
"n": "vFQ-FKvpOhgmcptUhCZk9Qi_Lc9ginBBdHVVfX7GBD1Lre3h2zBK0ZuqzKhrXjag-hMcyRVolyoPnfpCGmn-Jr2QtPAE0UjuG07wWf1I6dhg7dPHjkeWAEzDqT2tb244jnYKVPVzTj7X6L3BUveZfFiKqzGZp2peQSJ56Coe13XSRdtDUtoG1VYu50Ps9QJR6oKv9b0ujuKc7dhL_ea6vWrcgVLggKj02auQehLqZ8HOasmxPpr_LW0kcEwCShbHPc2qkgZ7YqNocxbSB9AdO1Fn3GRVAcY1huI3nLPQ4xL7bzmiinyEac0nPRfcyzIrtZI_3LHaNrW7lSbMWX-9tw",
"e": "AQAB"
},
{
"kty": "EC",
"use": "sig",
"alg": "ES256",
"kid": "novus-p7-ec-p256-2026",
"crv": "P-256",
"x": "W-DRtkDz4KfDgUk8eD0xdb-UrRrl_ciiSWwJ07uX7Ik",
"y": "9IE-5maLT4yN_XTTwuR2AEjeuENKSTwGqGGqhmQli-E"
},
{
"kty": "OKP",
"use": "sig",
"alg": "EdDSA",
"kid": "novus-p7-ed25519-2026",
"crv": "Ed25519",
"x": "gx7PZIbpm1_BzWSP9mJciBu6j1xkyVUqXgQcg7r-RBA"
}
]
}
Specifications
- Keys
- 3
- Algorithms
- RS256, ES256, EdDSA
- Kids
- novus-p7-rsa-2026, novus-p7-ec-p256-2026, novus-p7-ed25519-2026
- Matches
- the p7 certificate key pairs
- Sample Only
- true
- Seed
- 70117
Testing contract
Reference control- Scenario
- Point the JWT verifier's key resolver at this document and verify the p7 RS256 and EdDSA tokens.
- Expected result
- The resolver selects each token's key by kid and both signatures verify against the matching JWK.
What is a .json file?
JSON (JavaScript Object Notation) is a lightweight, text-based data-interchange format representing objects, arrays, strings, numbers, booleans, and null. It is language-independent, human-readable, and the dominant format for web APIs and configuration. It requires a single well-formed root value.
How to use this file
Use an example JSON file to test parsers and serializers, schema validation, Unicode and number-precision handling, and API request or response processing.
How to use this file for testing
“SAMPLE JWKS — RSA, EC, and Ed25519 Keys” is a deterministic Novus Examples fixture for JWT / JWKS testing, Certificate & key testing. Unsigned and SAMPLE-signed JWT variants plus JWKS documents — published sample material only, for auth parser tests.
Documented properties for this file: seed 70117. Compare results against paired or grouped companions on this page when present (clean↔damaged, searchable↔scanned, or format twins) so scores stay reproducible across runs.
Download the file once, keep the path stable in CI or local scripts, and treat the spec table as the contract: dimensions, seeds, field lists, and roles are intentional. Corrupt or invalid samples are labelled as such — expect parsers to fail loudly rather than silently accept them.
This is published, SAMPLE-only security material — never a real secret. Point certificate, key, or token parsers at it, test PEM/DER decoding and PKCS handling, and confirm your tooling reads the documented fields; any sample password is printed on this page.
These JSON fixtures are synthetic SAMPLE auth or tool-call shapes for harnesses — never production secrets or live tokens. Validate schema fields and alg variants against the documented role.
Code examples
import json
with open("jwks-multi-algorithm.json") as f:
data = json.load(f)
print(type(data), len(data))Related files
- pemSAMPLE RSA Public Key — SubjectPublicKeyInfoThe SAMPLE leaf's public key as a bare SubjectPublicKeyInfo (BEGIN PUBLIC KEY) — the form JWT verifiers and most language runtimes expect when you hand them a key rather than a certificate.

- jsonJWKS (Empty Keys) — SAMPLEEmpty JWKS keys array for edge-case JWKS loaders.

- jsonJWKS (RSA) — SAMPLESAMPLE JWKS document exposing the Wave G RSA public key for JWT signature verification tests.

- jsonSAMPLE JWK — EC P-256 Public KeyA single P-256 public JWK. Its x and y are fixed 32-byte base64url values, left-padded when a coordinate happens to be short — the padding rule that libraries stripping leading zeroes get wrong.

- jsonSAMPLE JWK — Ed25519 Private KeyAn OKP-type JWK holding the Ed25519 key pair as raw 32-byte x and d values. OKP is the newest JWK key type and the one older JOSE libraries reject outright.

- jsonSAMPLE JWK — RSA Private KeyThe full RSA private key as a JWK, including the CRT parameters p, q, dp, dq and qi. It is the input for testing JWK-to-PEM conversion, where dropping the CRT values quietly costs a large amount of signing performance.

Generated by generation/security_p7.py. Free for any use, no attribution required — license.