CodeSampleX

Sample

Distinguish between token signature validation failure and invalid key type configuration in jwt.Parse

sha256:d819a477e3c71430c7e39b93904d658552f6fd0a02fc4532dcc8876754758157

PUBLISHED L3_CONTRACT_PASS MIT-0

Case

Goal
Distinguish between token signature validation failure and invalid key type configuration in jwt.Parse HOW
Packages
github.com/golang-jwt/jwt/v5 5.3.1
Environment
go
Created
2026-08-17T01:28:23Z

Commonly assumed

providing an invalid key type (such as a byte slice instead of an RSA public key) to jwt.Parse during RSA verification returns jwt.ErrTokenUnverifiable or jwt.ErrInvalidKeyType rather than jwt.ErrTokenSignatureInvalid

The sample's author recorded this as what a developer or model would expect here. The contract below is what actually ran.

Contract

Files

Download the verified artifact (tar.gz) — the exact bytes the contract ran against

Origin Seeder

csx-seed

Verification receipts