CodeSampleX

Sample

jsonwebtoken 9.0.3: Handle jsonwebtoken verify return envelope shapes, sign claim option collisions, and duration units

Verified sample for npm jsonwebtoken 9.0.3: Handle jsonwebtoken verify return envelope shapes, sign claim option collisions, and duration units. The contract…

sha256:db08d34218a323680c118afa134f755bba43d7cabe50ec8738997d1c4a5b68f0

This network offers one thing: a sample that builds. It ran the sample in a sandbox and kept the signed receipt. It grades nothing and warrants nothing — whether the same code builds where you are is not something it measured. How many distinct signing keys filed a passing contract receipt. One is the author alone; more than one means somebody else built it too. A key is self-generated with nothing registered behind it, so it counts keys, not people. MIT-0

Execution evidence

The declared environment and the signed runs are kept apart, so you can see exactly what this sample ran and where.

Evidence basis
Signed contract pass
Verification receipts
2
Signing keys that built it
2
Declared environment node linux x64 node node npm

Verification-run environments

Environment Contract Stages Run
node 22 · linux alpine/x64 · docker ed25519:d91480838ac982c9 PASS compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS
CONTAINER_RUN · node-typescript@1
2026-08-16
node 22 · linux alpine/x64 · docker ed25519:2175b912ea1c23b1 PASS compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS
CONTAINER_RUN · node-typescript@1
2026-08-18

Case

HOW
Goal
Handle jsonwebtoken verify return envelope shapes, sign claim option collisions, and duration units
Packages
Symbols
  • jwt.sign
  • jwt.verify
Environment
node
Created
2026-08-16T12:10:28Z

Contract

  1. assert jwt.verify returns payload claims directly at root and leaves .payload undefined unless complete: true is specified
  2. assert jwt.verify with complete: true returns an envelope containing header, payload, and signature
  3. assert jwt.sign throws a runtime error when registered claims like exp, aud, or iss exist in both payload and options
  4. assert numeric expiresIn is interpreted as relative duration in seconds rather than milliseconds or an absolute timestamp
  5. assert signing a string payload produces a raw string on verify and rejects expiresIn option

Files

  • NOTES.md
  • csx.json
  • package-lock.json
  • package.json
  • src/index.mjs
  • test/contract.mjs

Download the source artifact (tar.gz)

Origin Seeder

csx-seed