Sample JWT: Decoded (JSON)
The decoded header and payload of the sample JWT as JSON, alongside the public signing secret and algorithm: the ground truth for checking a JWT decoder's output.
{
"header": {
"alg": "HS256",
"typ": "JWT"
},
"payload": {
"sub": "sample-user-01",
"name": "Example User",
"role": "demo",
"iss": "novus-examples",
"iat": 1767225600,
"exp": 1798761600,
"note": "SAMPLE TOKEN \u2014 signed with a public example secret. Not for production."
},
"signatureAlgorithm": "HS256",
"secret": "a-string-secret-at-least-256-bits-long",
"note": "Sample only. This token is signed with a public secret so it can be verified; it grants nothing and must never be used in production."
}
Specifications
- Format
- JSON
- Contents
- decoded JWT header + payload + secret
- Label
- SAMPLE ONLY
Testing contract
Expected to pass- Scenario
- Exercise Sample JWT: Decoded (JSON) in its security workflow. The decoded header and payload of the sample JWT as JSON, alongside the public signing secret and algorithm: the ground truth for checking a JWT decoder's output.
- Expected result
- top-level keys are header, payload, signatureAlgorithm, secret, note. Declared feature checks: contents=decoded JWT header + payload + secret; label=SAMPLE ONLY. The declared comparison counterpart is data-jwt; preserve the stated difference instead of expecting the container bytes to match.
What is a .json file?
JSON (JavaScript Object Notation) is a lightweight, text-based data-interchange format representing objects, arrays, strings, numbers, booleans, and null. It is language-independent, human-readable, and the dominant format for web APIs and configuration. It requires a single well-formed root value.
How to use this file
Use an example JSON file to test parsers and serializers, schema validation, Unicode and number-precision handling, and API request or response processing.
How to use this file for testing
“Sample JWT: Decoded (JSON)” is a deterministic Testaroo fixture for JSON parsing, Editor testing. Flat, deeply nested, JSON Lines, and intentionally invalid JSON for testing parsers and error handling.
Documented properties for this file: JSON. Compare results against paired or grouped companions on this page when present (clean↔damaged, searchable↔scanned, or format twins) so scores stay reproducible across runs.
Download the file once, keep the path stable in CI or local scripts, and treat the spec table as the contract: dimensions, seeds, field lists, and roles are intentional. Corrupt or invalid samples are labelled as such, expect parsers to fail loudly rather than silently accept them.
Data fixtures document their exact quirks (delimiters, encodings, null handling, schema, and row counts) in the spec table. Point your parser or importer at the file and assert it handles the documented edge cases; clean and deliberately-messy siblings make before/after diffs straightforward.
Feed the file to your parser and assert it handles the documented quirks, quoted delimiters, embedded newlines, ragged rows, or invalid syntax; the valid↔invalid distinction is labelled in the title.
Code examples
import json
with open("sample-jwt-decoded.json") as f:
data = json.load(f)
print(type(data), len(data))Generated by generation/q8_extras.py. Free for any use, no attribution required, license.
Related files
- jsonJSON Feed 1.1A JSON Feed 1.1 document (the JSON alternative to RSS/Atom) with a feed header and three items using content_html, content_text, tags, and publish dates, for testing JSON Feed parsers and readers.

- ipynbJupyter Notebook (IPYNB)A valid Jupyter notebook (nbformat 4.5) with markdown cells, code cells, and real outputs (stdout stream and an execute result), for testing notebook parsers, nbconvert, and JSON tooling.

- jsonCycloneDX 1.6 Application SBOM (JSON)A complete CycloneDX 1.6 SBOM in JSON for a fictional application and its nine dependencies, with purls, SHA-256 hashes, supplier records, external references and an explicit dependency graph. Every package, version, hash and licence is fictional: the tree describes nothing real.

- jsonSPDX 2.3 Application SBOM (JSON)An SPDX 2.3 SBOM in JSON describing the same fictional tree as the CycloneDX documents in this category, with SPDXIDs, purl external references, SHA-256 checksums and DESCRIBES/DEPENDS_ON relationships. Every package, version, hash and licence is fictional: the tree describes nothing real.

- csrCertificate Signing Request (CSR)A PKCS#10 certificate signing request (PEM) with the subject and SAN, self-signed by the RSA key to prove key possession, for testing CSR parsers and certificate-authority intake flows.

- keyEd25519 Private Key (PEM)An Ed25519 private key in PKCS#8 PEM, derived from a fixed seed: a published, sample-only modern elliptic-curve key for testing PEM parsers and Ed25519 tooling. Never use it for real.
