Sample
Enforce asymmetric key constraints including minimum RSA key size, EC named curve matching, and key roles
sha256:70b702f0bec4056d2b1d130f07f566fc2474c24141272abc15d93bb50ad32a34
PUBLISHED
L3_CONTRACT_PASS
MIT-0
Execution evidence
Declared environment and signed verification runs are separated so you can see exactly what this sample proves.
Evidence basisSigned contract pass
Verification receipts1
Verification levelL3_CONTRACT_PASS
Declared environment
- Execution context
- node
- Operating system
- linux
- Architecture
- x64
- Runtime
- node
- Language
- node
- Package manager
- npm
Verification-run environments
- Execution context
- node 22
- Operating system
- linux alpine · musl
- Architecture
- x64
- Runtime
- node 22
- Language
- javascript
- Package manager
- npm
- Execution
- container · docker
CONTAINER_RUN · compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS · node-typescript@1 · 2026-08-17
Case
- Goal
- Enforce asymmetric key constraints including minimum RSA key size, EC named curve matching, and key roles HOW
- Packages
-
jsonwebtoken 9.0.3
- Environment
- node
- Created
- 2026-08-17T20:01:32Z
Commonly assumed
jwt.sign accepts any valid RSA key modulus and any elliptic curve key with ES256, and jwt.verify handles dynamic key resolver callbacks synchronously.
The sample's author recorded this as what a developer or model would expect here. The contract below is what actually ran.
Contract
- Signing with an RSA key with modulus under 2048 bits throws an error by default unless allowInsecureKeySizes is explicitly enabled.
- assert jwt.sign verifies EC curve compatibility and rejects P-384 keys when ES256 is specified
- assert jwt.sign rejects symmetric keys and public keys when an asymmetric algorithm like RS256 is specified
- assert jwt.verify with a key resolver callback throws when invoked synchronously and requires an asynchronous completion callback
- assert native KeyObject instances are accepted directly for asymmetric signing and verification without PEM string serialization
Files
- NOTES.md
- csx.json
- package-lock.json
- package.json
- src/index.mjs
- test/contract.mjs
Download the source artifact (tar.gz)
Origin Seeder
csx-seed
Verification receipts
- node 22 · linux alpine/x64 · docker · CONTAINER_RUN · compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS · node-typescript@1 · 2026-08-17 · ed25519:d91480838ac982c9