Why negative tests matter
Most JWT vulnerabilities are verifiers that accept tokens they should reject. A happy-path test proves your API works; these cases prove it is safe. Point your API (in a test environment) at the generated secret or JWKS and assert that exactly one token is accepted.
Using the fixture
- Generate the set and copy the verification key into your API's test configuration.
- Copy all tokens as a JSON fixture and loop over them in your test suite.
- Assert a 2xx response for
validand a 401 for every other case.
Time-based tokens are relative to when you generated them; regenerate the set when the valid token expires (1 hour). To build a single token with custom claims, use the JWT encoder. To understand why a token is rejected, paste it into JWTDecoder.com.