PaymentApi

A usage-based JWT exercise/demo Web API. There's nothing to look at in a browser besides this page - everything else here is called with an HTTP client and a bearer token.

Endpoints

Method URL Access Description
GET /identity Any authenticated caller Returns every claim on the caller's token, verbatim. Use this first to see what a token (real or hand-crafted) actually produced.
GET /GetTime Any authenticated caller Returns the current server time. No scope or role required - only a valid token.
GET /payments scope=payment
role=finance
Returns every user's sample payment data. Callable by alice and bob.
GET /payments/newfeature scope=payment
role=developer
Returns the current server time. Callable by bob only.
GET /backchannellog None (public) Back-channel viewer - shows the discovery/JWKS calls this API makes to the Authority when validating RS256 tokens.

Tokens supported

These endpoints accept three different JWT signing modes, dispatched dynamically per-request based on the token's own (unvalidated) alg header. This is intentional - it's what makes the exercises possible - not a bug.

alg What it means
RS256 A real token, cryptographically validated against the live Authority: https://identityservice.secure.nu.
HS256 Signed with a shared symmetric secret known to anyone working through the exercise - not a trusted signature.
none A completely unsigned token (RFC 7519 "unsecured JWT"). Claims are trusted with zero cryptographic verification.