A usage-based JWT exercise/demo Web API. There's nothing to look at in a browser besides this page - everything else here is called with an HTTP client and a bearer token.
| Method | URL | Access | Description |
|---|---|---|---|
| GET | /identity |
Any authenticated caller | Returns every claim on the caller's token, verbatim. Use this first to see what a token (real or hand-crafted) actually produced. |
| GET | /GetTime |
Any authenticated caller | Returns the current server time. No scope or role required - only a valid token. |
| GET | /payments |
scope=paymentrole=finance |
Returns every user's sample payment data. Callable by alice and bob. |
| GET | /payments/newfeature |
scope=paymentrole=developer |
Returns the current server time. Callable by bob only. |
| GET | /backchannellog | None (public) | Back-channel viewer - shows the discovery/JWKS calls this API makes to the Authority when validating RS256 tokens. |
These endpoints accept three different JWT signing modes, dispatched dynamically
per-request based on the token's own (unvalidated) alg header. This is intentional -
it's what makes the exercises possible - not a bug.
| alg | What it means |
|---|---|
RS256 |
A real token, cryptographically validated against the live Authority: https://identityservice.secure.nu. |
HS256 |
Signed with a shared symmetric secret known to anyone working through the exercise - not a trusted signature. |
none |
A completely unsigned token (RFC 7519 "unsecured JWT"). Claims are trusted with zero cryptographic verification. |