invalid algorithm 🔐 Authentication

JWT error: invalid algorithm / The specified alg value is not allowed / jwt signature is required

The token’s alg header doesn’t match the algorithms the verifier allows — e.g. RS256 token verified as HS256, or an unsigned (alg: none) token.

Seen on: REST API

Meaning

Verifiers must pin allowed algorithms. Mixing HS256 secrets with RS256 tokens (or the reverse), copying keys in the wrong format, or tampered tokens produce these errors.

Common causes

  • Verifying RS256 tokens with an HS256 secret (or vice versa)
  • algorithms option not matching the issuer
  • Token with alg none / unsigned
  • Wrong key format (PEM vs JWK)

⚡ Quick fix

  1. Set algorithms explicitly to the issuer’s algorithm
  2. Use the issuer’s public key/JWKS for RS256/ES256
  3. Reject unsigned tokens

Detailed fix by platform

JavaScript

  1. jwt.verify(token, publicKeyPem, { algorithms: ["RS256"], issuer: "https://auth.example.com/", audience: "api://orders" });

Python

  1. jwt.decode(token, key, algorithms=["RS256"], audience="api://orders")

How to diagnose

  1. Header — alg in the token (decode header)
  2. Verifier — Allowed algorithms and key type

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.