Skip to main content

Developer

JWT Verifier

Verify JWT signatures locally with WebCrypto—HS*, RS*, and ES256.

No registration
  • On your device

Browse more in Developer or all tools.

Private on your device

Your information stays on your device and is not uploaded.

Paste a JWT and provide the matching HMAC secret or PEM public key to verify its signature on your device. Supports HS256/384/512, RS256/384/512, and ES256 with clear success or failure messaging. Decoding alone does not prove authenticity—this tool verifies signatures locally with no server calls.

How to use this tool

1. Paste the JWT (Bearer prefix optional). 2. Provide the HMAC secret or PEM public key that should verify it. 3. Choose the algorithm if needed. 4. Confirm success or failure before trusting claims in your app.

Worked example

Example: an HS256 token signed with secret "dev-secret" verifies successfully; changing one payload character fails signature check.

How it works

Paste a JWT and provide the matching HMAC secret or PEM public key. Signature verification uses WebCrypto locally—HS256/384/512, RS256/384/512, and ES256 are supported. Decoding alone does not prove authenticity.

Limitations

Results are based on the inputs you provide and may not cover every edge case. This tool is for general use and is not professional advice.

Privacy and file handling

Your data stays on your device and is not uploaded.

FAQ

Frequently asked questions

Is JWT Verifier free?

Yes. It is free to use and you do not need to sign in or create an account.

Is my data private?

See the privacy note on this page. Many tools run on your device; some heavier file tools may use secure temporary processing when required.

Can I use JWT Verifier on mobile?

Yes. Open this page on your phone or tablet, enter your inputs, and use the on-screen controls.

Page last reviewed: