JWT Signature Verifier
Check whether a JWT's signature is valid. Paste the token, then the HMAC secret or the issuer's public key (PEM, JWK or JWKS), and the verifier tells you if the signature matches — and whether the token is expired or not yet valid.
Paste the JWT; the algorithm is read from its header. For HS256/384/512 enter the shared secret (text, Base64 or hex); for RS, PS and ES algorithms paste the public key as SPKI PEM, a JWK or a JWKS. Click Verify to see a clear valid/invalid result, plus the decoded header and payload. Tokens with alg “none” are always rejected.
Zero Server Uploads
Files process in local RAM
Instant WASM Speed
No waiting queues or lags
Unlimited Batching
Convert files without limits
Suggest a Feature or Improvement for JWT Signature Verifier
Need custom options, higher limits, or extra format support? Let our engineering team know!
How to use JWT Signature Verifier
- 1Paste the token.
- 2Enter the secret or public key.
- 3Click Verify signature.
- 4Check the result and the token's time claims.
Decoding vs verifying
Decoding just base64url-decodes the header and payload — anyone can do it. Verifying recomputes the signature with the key and proves the token was issued by the key holder and not modified. Servers must always verify before trusting any claim.
A valid signature isn't the whole story: servers should also check exp, nbf, the issuer (iss) and audience (aud), and only accept the algorithms they expect.
Common failures
An invalid signature usually means the wrong key (test vs production, rotated keys — check the kid header), a secret entered as text when it should be Base64-decoded, or a token copied with extra characters. The alg “none” attack and HS/RS key confusion are why libraries must pin the expected algorithm. Create test tokens with the JWT Generator.
Frequently Asked Questions
Where do I get the public key?
From the issuer's JWKS endpoint, usually https://issuer/.well-known/jwks.json. Paste the whole JWKS; the first key is used, so pick the one whose kid matches the token header.
Is my token sent anywhere?
No. Verification uses the Web Crypto API in your browser.
Is it free? Do I need an account?
It's completely free with no sign-up and no daily credits.