JWT error: invalid algorithm / The specified alg value is not allowed / jwt signature is required
The token’s alg header doesn’t match the algorithms the verifier allows — e.g. RS256 token verified as HS256, or an unsigned (alg: none) token.
Seen on:
REST API
Meaning
Verifiers must pin allowed algorithms. Mixing HS256 secrets with RS256 tokens (or the reverse), copying keys in the wrong format, or tampered tokens produce these errors.
Common causes
- Verifying RS256 tokens with an HS256 secret (or vice versa)
- algorithms option not matching the issuer
- Token with alg none / unsigned
- Wrong key format (PEM vs JWK)
⚡ Quick fix
- Set algorithms explicitly to the issuer’s algorithm
- Use the issuer’s public key/JWKS for RS256/ES256
- Reject unsigned tokens
Detailed fix by platform
JavaScript
jwt.verify(token, publicKeyPem, { algorithms: ["RS256"], issuer: "https://auth.example.com/", audience: "api://orders" });
Python
jwt.decode(token, key, algorithms=["RS256"], audience="api://orders")
How to diagnose
- Header — alg in the token (decode header)
- Verifier — Allowed algorithms and key type
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
- 0x800704EC 0x800704EC: This program is blocked by group policy (Windows Defender)
- 1005 Cloudflare Error 1005: Access denied — The owner of this website has banned the autonomous system number (ASN) your IP address is in
- 1006 Cloudflare Error 1006 / 1007 / 1008: Access denied — Your IP address has been banned
Most viewed in Authentication
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026