That page doesn't exist. Search or drop a file below to find the tool you need.
What do you need to get done?
- Stays on this device
- No watermark
- Works offline
Drop a file here
or .
Open an app
Follow a recipe
Use one tool
JWT verifier
Check whether a JWT's signature is valid. Paste the token, then enter the secret (HS256/384/512) or the public key as PEM or JWK (RS, PS and ES) and see "Signature verified" or "Not verified". It runs in your browser: token and key are never uploaded.
How to verify a JWT signature
- 1Paste the token
- 2Enter the secret, or paste the public key (PEM or JWK)
- 3Read the verdict under the key
- Signature verified, or a clear reason why not.
What happens to your token and key
- Nothing is uploaded.Token, secret and key are used by your browser's own crypto, on your device.
- Plain verdict.A green or red badge, plus a sentence on why the check passed or failed.
- Fits the algorithm.The tool asks for a secret or a public key, depending on the token's alg.
What you can do
- Verify HS256, HS384 and HS512 tokens with a shared secret, and tick "Secret is Base64" if the secret is Base64 encoded.
- Verify RS256/384/512, PS256/384/512 and ES256/384/512 tokens with a public key in PEM (-----BEGIN PUBLIC KEY-----) or JWK form.
- Take the first key if you paste a whole JWK set with a "keys" list.
- Show the decoded header, payload and expiry as well, so you see what you just verified.
- Reject tokens with alg "none" and say why: nobody signed them.
Good to know
- Only the signature is checked. The verdict does not say whether the token has expired. The expiry badge above shows that separately.
- The verifier needs a public key, not a certificate or a private key. For a certificate, extract the key first: openssl x509 -in cert.pem -pubkey -noout.
- An RSA key that starts with BEGIN RSA PUBLIC KEY (PKCS#1) must be converted to a standard public key first.
- Treat real tokens like passwords. Nothing leaves your browser, but use a test token whenever you can.
Questions
How do I verify a JWT signature?
Paste the token. For an HS token, enter the secret. For RS, PS or ES, paste the public key. The result shows at once.
Why does it say "Not verified"?
Either the secret or key is wrong, or the token was changed after it was signed. A key of the wrong type or curve gets its own message.
Does it check that the token has not expired?
No. It checks the signature only. The expiry shows as a separate badge, so check both before you trust a token.
Is my secret or public key uploaded?
No. The check runs in your browser. Neither the token nor the key is sent anywhere.