typescriptMITTrust: scanned

HS256 JWT sign + verify (zero dependency, constant-time)

A reusable HS256 JWT signing and verification utility with constant-time signature comparison and exp/nbf validation.

Auth path — what to verify before you trust it

Auth flows fail silently: skipped signature/nonce checks, missing email-verification gates, replayable tokens. Verify those hold in any auth snippet — including this one — before trusting it.

Preview

90 lines
// aperçu protégé · typescript · 90 lignes

90 more lines are delivered on retrieval, with the full verified card and its proof receipt.

What you get on retrieval

  • · The complete verified implementation, written to bytes by the MCP tool (near-zero output tokens).
  • · A proof receipt: source provenance, review status, license state and estimated savings.
  • · Revocation coverage — if a security fix lands on this primitive, retrievers are notified.