Verify or sign a JWT
Check a JWT signature with a shared secret or a public key, or sign a test token with HS256. WebCrypto runs on this page and the key is never stored.
JWT sign and verify in three steps
Check whether a JSON Web Token was really signed by the key you expect, or make a signed test token for a local development server, without pasting either the token or the key into somebody else’s website. The work is done by WebCrypto, the cryptography built into your browser, on this page.
Verification answers one question: did the holder of this key sign exactly these bytes. If a single character of the header or payload changed after signing, the answer is no. The result says which algorithm was checked and against which kind of key, then lists anything a server would still refuse: an exp in the past, an nbf in the future, or a token with no expiry at all.
Some tokens are refused rather than checked, and the reason is given. A token whose header says alg: none is unsigned and is never called valid. A token that claims HS256 is not checked against a public key, since that mismatch is how algorithm-confusion forgeries work. A private key is refused outright, because verifying never needs one.
Signing is limited to HS256, HS384 and HS512 with a shared secret, which is what local test setups usually use. The payload is signed exactly as typed, so a long numeric ID keeps every digit. A secret shorter than the hash is flagged, as RFC 7518 section 3.2 requires at least that length.
Nothing here replaces verification on your server. Checking a token by hand tells you whether the key matches; your application still has to check the issuer, the audience and its own rules.
- 1
Paste the token
- 2
Paste the shared secret or the public key that should have signed it
- 3
Read whether the signature matches and what the timing claims say
Frequently asked questions
Which algorithms can it check?
HS256, HS384 and HS512 with a shared secret, and RS, PS and ES at 256, 384 or 512 with a public key. Signing covers the three HS algorithms, because signing with RS or ES would mean pasting a private key into a web page.
What kind of public key can I paste?
A PEM public key, an RSA PUBLIC KEY block, a PEM certificate, a single JWK, or a JWK set. From a set, the key whose kid matches the token header is used.
Is the secret stored anywhere?
No. It is read when you press the button, used by the browser's WebCrypto, and dropped. It is not saved with your settings, Clear empties the field, and leaving the page empties it too.
Why does it refuse an HS256 token when I paste a public key?
Because checking an HS token against a public key is a known forgery. A public key is not secret, so if a verifier used it as an HMAC secret, anyone could sign tokens it accepts. The key type has to match the algorithm family.