Standard JSON Web Token (JWT) issuance, verification, and role resolution. Authenticate against built-in developer test personas, decode signed HMAC-SHA256 claims, and access protected endpoints using standard Bearer authorization headers.
Choose a pre-configured role persona below to load credentials into the interactive login console:
Transmits credentials to issue a signed access token (15m expiry) and long-lived refresh token:
Access protected user identity and claims using the session cookie or by passing the issued Bearer token:
Apply partial mutations to your active user profile. Changes are stored in your session overlay without mutating baseline seed records:
Create an ad-hoc user account within your isolated sandbox session and immediately receive a signed JWT token pair:
Access tokens issued by Playground API are signed with HMAC-SHA256 and encode identity and authorization claims:
{
"alg": "HS256",
"typ": "JWT"
}Cryptographic signature algorithm metadata.
{
"userId": 1,
"username": "admin",
"role": "ADMIN",
"scopes": ["read:all","write:all","admin:all","sandbox:reset"],
"iat": 1759140000,
"exp": 1759140900
}Identity, role permissions, and UNIX expiry timestamps.
HMACSHA256( base64Url(header) + "." + base64Url(payload), JWT_SECRET )
Tamper-evident verification hash ensuring authenticity.
Production-ready authorization interceptors and route protection patterns: