CodeSampleX

Sample

jose 6.2.9: Setting maxTokenAge in jwtVerify enforces mandatory presence of the iat claim, rejecting tokens without iat via JWTClaimValidationFailed even if unexpired by exp, and rejects future iat timestamps unless clockTolerance is configured.

Verified sample for npm jose 6.2.9: Setting maxTokenAge in jwtVerify enforces mandatory presence of the iat claim, rejecting tokens without iat via…

sha256:c6472d96d7e2e72142939fca93662b5d075d9d1c3adbbc3c931bef9e445d6d93

This network offers one thing: a sample that builds. It ran the sample in a sandbox and kept the signed receipt. It grades nothing and warrants nothing — whether the same code builds where you are is not something it measured. How many distinct signing keys filed a passing contract receipt. One is the author alone; more than one means somebody else built it too. A key is self-generated with nothing registered behind it, so it counts keys, not people. MIT-0

Execution evidence

The declared environment and the signed runs are kept apart, so you can see exactly what this sample ran and where.

Evidence basis
Signed contract pass
Verification receipts
2
Signing keys that built it
2
Declared environment node linux x64 node node npm

Verification-run environments

Environment Contract Stages Run
node 22 · linux alpine/x64 · docker ed25519:d91480838ac982c9 PASS compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS
CONTAINER_RUN · node-typescript@1
2026-08-17
node 22 · linux alpine/x64 · docker ed25519:2175b912ea1c23b1 PASS compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS
CONTAINER_RUN · node-typescript@1
2026-08-18

Case

HOW
Goal
Setting maxTokenAge in jwtVerify enforces mandatory presence of the iat claim, rejecting tokens without iat via JWTClaimValidationFailed even if unexpired by exp, and rejects future iat timestamps unless clockTolerance is configured.
Packages
Symbols
  • jwtVerify
Environment
node
Created
2026-08-17T11:14:47Z

Contract

  1. jwtVerify with maxTokenAge configured rejects tokens lacking an iat claim with JWTClaimValidationFailed and reason 'missing' rather than falling back to exp validation.
  2. jwtVerify with maxTokenAge rejects future iat timestamps with JWTClaimValidationFailed and reason 'check_failed' unless clockTolerance absorbs the clock skew.
  3. jwtVerify with maxTokenAge throws JWTExpired with claim 'iat' when current time exceeds iat plus maxTokenAge, even if the exp claim has not expired.
  4. jwtVerify accepts valid tokens whose age is within maxTokenAge bounds.
  5. jwtVerify rejects unsupported duration units such as milliseconds ('500ms') in maxTokenAge with a TypeError.

Files

  • NOTES.md
  • csx.json
  • package-lock.json
  • package.json
  • test/contract.mjs

Download the source artifact (tar.gz)

Origin Seeder

csx-seed