Skip to content
FlexibleToolsAI
Security Toolkit · 100% Client-Side Private

JWT Signature Verifier

Check whether a JWT's signature is valid. Paste the token, then the HMAC secret or the issuer's public key (PEM, JWK or JWKS), and the verifier tells you if the signature matches — and whether the token is expired or not yet valid.

Paste the JWT; the algorithm is read from its header. For HS256/384/512 enter the shared secret (text, Base64 or hex); for RS, PS and ES algorithms paste the public key as SPKI PEM, a JWK or a JWKS. Click Verify to see a clear valid/invalid result, plus the decoded header and payload. Tokens with alg “none” are always rejected.

Decoding a JWT only reads it; verifying proves it was signed with the matching key and hasn't been modified. Your token and key never leave the browser.

Zero Server Uploads

Files process in local RAM

Instant WASM Speed

No waiting queues or lags

Unlimited Batching

Convert files without limits

Suggest a Feature or Improvement for JWT Signature Verifier

Need custom options, higher limits, or extra format support? Let our engineering team know!

How to use JWT Signature Verifier

  1. 1Paste the token.
  2. 2Enter the secret or public key.
  3. 3Click Verify signature.
  4. 4Check the result and the token's time claims.

Decoding vs verifying

Decoding just base64url-decodes the header and payload — anyone can do it. Verifying recomputes the signature with the key and proves the token was issued by the key holder and not modified. Servers must always verify before trusting any claim.

A valid signature isn't the whole story: servers should also check exp, nbf, the issuer (iss) and audience (aud), and only accept the algorithms they expect.

Common failures

An invalid signature usually means the wrong key (test vs production, rotated keys — check the kid header), a secret entered as text when it should be Base64-decoded, or a token copied with extra characters. The alg “none” attack and HS/RS key confusion are why libraries must pin the expected algorithm. Create test tokens with the JWT Generator.

Frequently Asked Questions

Where do I get the public key?

From the issuer's JWKS endpoint, usually https://issuer/.well-known/jwks.json. Paste the whole JWKS; the first key is used, so pick the one whose kid matches the token header.

Is my token sent anywhere?

No. Verification uses the Web Crypto API in your browser.

Is it free? Do I need an account?

It's completely free with no sign-up and no daily credits.

Guides & Tutorials

Related Tools