ToolRecipe

What do you need to get done?

Drop a file here

or .

Open an app

Follow a recipe

All recipes

Use one tool

All tools

JWT verifier

Check whether a JWT's signature is valid. Paste the token, then enter the secret (HS256/384/512) or the public key as PEM or JWK (RS, PS and ES) and see "Signature verified" or "Not verified". It runs in your browser: token and key are never uploaded.

How to verify a JWT signature

  1. 1Paste the token
  2. 2Enter the secret, or paste the public key (PEM or JWK)
  3. 3Read the verdict under the key
  4. Signature verified, or a clear reason why not.

What happens to your token and key

  • Nothing is uploaded.Token, secret and key are used by your browser's own crypto, on your device.
  • Plain verdict.A green or red badge, plus a sentence on why the check passed or failed.
  • Fits the algorithm.The tool asks for a secret or a public key, depending on the token's alg.

What you can do

  • Verify HS256, HS384 and HS512 tokens with a shared secret, and tick "Secret is Base64" if the secret is Base64 encoded.
  • Verify RS256/384/512, PS256/384/512 and ES256/384/512 tokens with a public key in PEM (-----BEGIN PUBLIC KEY-----) or JWK form.
  • Take the first key if you paste a whole JWK set with a "keys" list.
  • Show the decoded header, payload and expiry as well, so you see what you just verified.
  • Reject tokens with alg "none" and say why: nobody signed them.

Good to know

  • Only the signature is checked. The verdict does not say whether the token has expired. The expiry badge above shows that separately.
  • The verifier needs a public key, not a certificate or a private key. For a certificate, extract the key first: openssl x509 -in cert.pem -pubkey -noout.
  • An RSA key that starts with BEGIN RSA PUBLIC KEY (PKCS#1) must be converted to a standard public key first.
  • Treat real tokens like passwords. Nothing leaves your browser, but use a test token whenever you can.

Questions

How do I verify a JWT signature?

Paste the token. For an HS token, enter the secret. For RS, PS or ES, paste the public key. The result shows at once.

Why does it say "Not verified"?

Either the secret or key is wrong, or the token was changed after it was signed. A key of the wrong type or curve gets its own message.

Does it check that the token has not expired?

No. It checks the signature only. The expiry shows as a separate badge, so check both before you trust a token.

Is my secret or public key uploaded?

No. The check runs in your browser. Neither the token nor the key is sent anywhere.

How it works

Small tools that run in your browser.

Four steps

  1. Start with a file or a task

    Drop a file, search, or pick a task.

  2. The tool opens in a window

    Open as many as you like, side by side as tabs.

  3. Results collect on the right

    Drag a result into the next tool.

  4. Save when you're done

    Saved files go to your downloads.

Who uses what

Tool sets for common jobs.

Put a tool on your home screen

The icon opens that tool, like an app.

iPhone and iPad

  1. Open the tool in Safari.
  2. Tap Share (the square with the arrow).
  3. Choose “Add to Home Screen”, then Add.

Android

  1. Open the tool in Chrome.
  2. Tap the menu (⋮) at the top right.
  3. Choose “Add to Home screen” or “Install app”.

Computer

  1. Open the tool in Chrome or Edge.
  2. Click the install icon in the address bar.
  3. Choose Install.

Skills

Claude skills we use ourselves, one job each.