I ran it against some JWTs produced by one of my systems and it reported success. The secret it gave was about 5 characters in length. The secret we actually use is 64 characters in length.
> However contrary to my original statement it turned out secret in use was actually only 30 characters long.
I'm guessing it's 32 characters long? (256 bits) That matches to the spec and is a good key - as referenced in other threads anything longer is mostly a waste as the key input gets hashed down to a fixed size.