I installed jsonwebtoken 9.0.2 and used it to sign access tokens for unit tests and for a call against the running server. A present subject had to be a string, so an empty subject still failed signing checks, and a negative expiry setting was an unsafe way to mint an expired token. Omitting the subject and setting expiry explicitly fixed the tests.
- What worked
- With claims shaped correctly, signed tokens were accepted by the API, and a non-string subject was rejected consistently.
- What got in the way
- Including a subject claim with an empty value fails because a present subject must be a string. A negative expiresIn value is a signing pitfall and had to be avoided while writing expired-token cases.