Skip to content
Novus Examples
jwt720 B

SAMPLE JWT — RS256, Not Yet Valid

A valid signature over a claim set whose nbf is 2035. Many verifiers check exp diligently and skip nbf entirely, so this is the token that finds out.

Preview — first 2 linesjwt
eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6Im5vdnVzLXA3LXJzYS0yMDI2In0.eyJpc3MiOiJodHRwczovL2lzc3Vlci5wa2kuc2FtcGxlLmV4YW1wbGUvIiwic3ViIjoidXNlci1zYW1wbGUtMDAwMSIsImF1ZCI6Im5vdnVzLXA3LXNhbXBsZS1hcGkiLCJpYXQiOjE3NjcyMjU2MDAsIm5iZiI6MjA1MTIyMjQwMCwiZXhwIjoyMDgyNzU4NDAwLCJqdGkiOiJub3Z1cy1wNy1zYW1wbGUtMDAwMSIsIm5hbWUiOiJTYW0gUml2ZXJhIChTQU1QTEUpIiwic2NvcGUiOiJyZWFkOnNhbXBsZSJ9.QYciJ0RByi9fc9HfKoOLur4uMRtb1JB08HU86zEwp9rzaF_tcAl_Z1YJ53wbbSq3W2ObToFjc8i4UgnVRZmwWkoMw96r3nJiSxLyM9Dg_5HCX1E5vOPw0zy8FIdQ-5C9p-8l7xnDFL5lij3YOltPu3gjuq0_444SywcAyz5AxgGIMf09u0Q4HFdvfsgaBc2_frQNrDsu1qCVGgJacFtkeLK6DLzTOhmB8cuFolQ5F1Qd4MSl7qB-nLBXAth7QXCj880RQY_9iKiNMs7RwemUdQpsh0USaZx2LJo2_Giytpu8iWSFfOxaDlg7l1t_sj-TjT1-ckixA9pXxlyLmpfHOg

Specifications

Alg
RS256
Kid
novus-p7-rsa-2026
Nbf
2051222400
Not Before
2035-01-01
Valid
false
Sub
user-sample-0001
Sample Only
true
Seed
70117

Testing contract

Expected to fail
Scenario
Verify the token at a present-day clock with default validation settings.
Expected result
Validation fails on the nbf claim; a verifier that ignores nbf incorrectly accepts the token.

What is a .jwt file?

A JWT (JSON Web Token) is a compact, URL-safe token made of three base64url-encoded parts — a header, a payload of claims, and a signature — separated by dots. It is widely used to carry authentication and authorisation claims between services.

How to use this file

Use a sample JWT to test token decoding, claim extraction, and signature verification. Never use an example token's secret in production.

How to use this file for testing

“SAMPLE JWT — RS256, Not Yet Valid” is a deterministic Novus Examples fixture for JWT / JWKS testing, Error handling. Unsigned and SAMPLE-signed JWT variants plus JWKS documents — published sample material only, for auth parser tests.

Documented properties for this file: seed 70117 · intentionally invalid. Compare results against paired or grouped companions on this page when present (clean↔damaged, searchable↔scanned, or format twins) so scores stay reproducible across runs.

Download the file once, keep the path stable in CI or local scripts, and treat the spec table as the contract: dimensions, seeds, field lists, and roles are intentional. Corrupt or invalid samples are labelled as such — expect parsers to fail loudly rather than silently accept them.

This is published, SAMPLE-only security material — never a real secret. Point certificate, key, or token parsers at it, test PEM/DER decoding and PKCS handling, and confirm your tooling reads the documented fields; any sample password is printed on this page.

These JSON fixtures are synthetic SAMPLE auth or tool-call shapes for harnesses — never production secrets or live tokens. Validate schema fields and alg variants against the documented role.

Code examples

cut -d. -f1 jwt-rs256-not-yet-valid.jwt | base64 -d; echo
cut -d. -f2 jwt-rs256-not-yet-valid.jwt | base64 -d; echo    # payload claims

Generated by generation/security_p7.py. Free for any use, no attribution required — license.