SAMPLE JWT — RS256, Valid
The reference token for this wave: RS256, signed by the SAMPLE leaf key, with iss, aud, iat, nbf, exp and jti all present and an expiry in 2036. Every other JWT here is a deliberate deviation from it.
eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6Im5vdnVzLXA3LXJzYS0yMDI2In0.eyJpc3MiOiJodHRwczovL2lzc3Vlci5wa2kuc2FtcGxlLmV4YW1wbGUvIiwic3ViIjoidXNlci1zYW1wbGUtMDAwMSIsImF1ZCI6Im5vdnVzLXA3LXNhbXBsZS1hcGkiLCJpYXQiOjE3NjcyMjU2MDAsIm5iZiI6MTc2NzIyNTYwMCwiZXhwIjoyMDgyNzU4NDAwLCJqdGkiOiJub3Z1cy1wNy1zYW1wbGUtMDAwMSIsIm5hbWUiOiJTYW0gUml2ZXJhIChTQU1QTEUpIiwic2NvcGUiOiJyZWFkOnNhbXBsZSJ9.QjfU_T3uAz6HOpDAuyTWKA83R0TMcbPIFr02PAt2DLr5AwG7ST9ILBsZGKBWBmCd943WbdXvdgu9n2G4csGaCThIHKiB5QzCI8RL-Wm8rOJOT4nGt5FxkKla2WN14EVImoe8Ah73mPscRc60DNlaJ85GbUiYdlFLb-u18yeovIlf--x8kKVJjlZWAVm3_CcMTWzkjvnOptzmII6wZWq6Sf5xlXVW36I4OsnlQfTa7q1H0tzYaZb8bOJrYStYwXBSjJhB5dOvn81kKo59PEVPlSI7xa0HdKJ9ca64nF-4XXiIoNV7rLA6STpjOoPcNDO_gW3XhYcfpXgcyCmnirr_hA
Specifications
- Alg
- RS256
- Kid
- novus-p7-rsa-2026
- Exp
- 2082758400
- Iss
- https://issuer.pki.sample.example/
- Aud
- novus-p7-sample-api
- Valid
- true
- Sub
- user-sample-0001
- Sample Only
- true
- Seed
- 70117
Testing contract
Expected to pass- Scenario
- Verify the token against the p7 JWK set with issuer and audience checks enabled.
- Expected result
- All signature, iss, aud, nbf and exp checks pass and the claim set is returned.
What is a .jwt file?
A JWT (JSON Web Token) is a compact, URL-safe token made of three base64url-encoded parts — a header, a payload of claims, and a signature — separated by dots. It is widely used to carry authentication and authorisation claims between services.
How to use this file
Use a sample JWT to test token decoding, claim extraction, and signature verification. Never use an example token's secret in production.
How to use this file for testing
“SAMPLE JWT — RS256, Valid” is a deterministic Novus Examples fixture for JWT / JWKS testing. Unsigned and SAMPLE-signed JWT variants plus JWKS documents — published sample material only, for auth parser tests.
Documented properties for this file: seed 70117. Compare results against paired or grouped companions on this page when present (clean↔damaged, searchable↔scanned, or format twins) so scores stay reproducible across runs.
Download the file once, keep the path stable in CI or local scripts, and treat the spec table as the contract: dimensions, seeds, field lists, and roles are intentional. Corrupt or invalid samples are labelled as such — expect parsers to fail loudly rather than silently accept them.
This is published, SAMPLE-only security material — never a real secret. Point certificate, key, or token parsers at it, test PEM/DER decoding and PKCS handling, and confirm your tooling reads the documented fields; any sample password is printed on this page.
These JSON fixtures are synthetic SAMPLE auth or tool-call shapes for harnesses — never production secrets or live tokens. Validate schema fields and alg variants against the documented role.
Code examples
cut -d. -f1 jwt-rs256-valid.jwt | base64 -d; echo
cut -d. -f2 jwt-rs256-valid.jwt | base64 -d; echo # payload claimsRelated files
- jwtJWT — Intentionally Invalid SegmentsIntentionally invalid JWT (truncated) for parser error-path tests.

- jwtJWT (HS256 Expired) — SAMPLESAMPLE HS256 JWT with a past exp claim — for expiry-validation harnesses.

- jwtJWT (HS256) — SAMPLESAMPLE JWT with alg=HS256 for auth parsers and algorithm-handling tests. Published sample material only.

- jwtJWT (HS384) — SAMPLESAMPLE JWT with alg=HS384 for auth parsers and algorithm-handling tests. Published sample material only.

- jwtJWT (HS512) — SAMPLESAMPLE JWT with alg=HS512 for auth parsers and algorithm-handling tests. Published sample material only.

- jwtJWT (none) — SAMPLESAMPLE JWT with alg=none for auth parsers and algorithm-handling tests. Published sample material only.

Generated by generation/security_p7.py. Free for any use, no attribution required — license.