JWT (HS256) — SAMPLE
SAMPLE JWT with alg=HS256 for auth parsers and algorithm-handling tests. Published sample material only.
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiJ1c2VyLXNhbXBsZS0wMDEiLCJpc3MiOiJodHRwczovL2F1dGguc2FtcGxlLmV4YW1wbGUvIiwiYXVkIjoibm92dXMtYXBpLXNhbXBsZSIsImlhdCI6MTc2NzIyNTYwMCwiZXhwIjoxNzY3MzEyMDAwLCJuYW1lIjoiU2FtIFJpdmVyYSBTQU1QTEUifQ.r2bn1Cs7UKaI9lHclz2UE7w26Akoe3a6Hr5cPNSuiuc
Specifications
- Alg
- HS256
- Typ
- JWT
- Sample Only
- true
- Seed
- 47001
- Hs Secret
- novus-wave-g-jwt-sample-secret-do-not-use
What is a .jwt file?
A JWT (JSON Web Token) is a compact, URL-safe token made of three base64url-encoded parts — a header, a payload of claims, and a signature — separated by dots. It is widely used to carry authentication and authorisation claims between services.
How to use this file
Use a sample JWT to test token decoding, claim extraction, and signature verification. Never use an example token's secret in production.
How to use this file for testing
“JWT (HS256) — SAMPLE” is a deterministic Novus Examples fixture for JWT / JWKS testing. Unsigned and SAMPLE-signed JWT variants plus JWKS documents — published sample material only, for auth parser tests.
Documented properties for this file: seed 47001. Compare results against paired or grouped companions on this page when present (clean↔damaged, searchable↔scanned, or format twins) so scores stay reproducible across runs.
Download the file once, keep the path stable in CI or local scripts, and treat the spec table as the contract: dimensions, seeds, field lists, and roles are intentional. Corrupt or invalid samples are labelled as such — expect parsers to fail loudly rather than silently accept them.
This is published, SAMPLE-only security material — never a real secret. Point certificate, key, or token parsers at it, test PEM/DER decoding and PKCS handling, and confirm your tooling reads the documented fields; any sample password is printed on this page.
These JSON fixtures are synthetic SAMPLE auth or tool-call shapes for harnesses — never production secrets or live tokens. Validate schema fields and alg variants against the documented role.
Code examples
cut -d. -f1 sample-hs256.jwt | base64 -d; echo
cut -d. -f2 sample-hs256.jwt | base64 -d; echo # payload claimsRelated files
- jwtJWT — Intentionally Invalid SegmentsIntentionally invalid JWT (truncated) for parser error-path tests.

- jwtJWT (HS256 Expired) — SAMPLESAMPLE HS256 JWT with a past exp claim — for expiry-validation harnesses.

- jsonJWT Header Claims — RS256 SAMPLEJWT Header Claims — RS256 SAMPLE — unsigned JSON companion for claim-parser tests (not a live token).

- jsonJWT Payload — Expired SAMPLEJWT Payload — Expired SAMPLE — unsigned JSON companion for claim-parser tests (not a live token).

- jsonJWKS (Empty Keys) — SAMPLEEmpty JWKS keys array for edge-case JWKS loaders.

- jsonJWKS (RSA) — SAMPLESAMPLE JWKS document exposing the Wave G RSA public key for JWT signature verification tests.

Generated by generation/security_wave_g.py. Free for any use, no attribution required — license.