Decode a token, check the signature, or sign a test token in the browser. HMAC, RSA and ECDSA. The token is not uploaded. A JWKS address is fetched only when you ask.
Verify with JWKS fetches that address from this browser and downloads keys only. The token stays on this page. The address must allow a browser request.
HS uses the secret. RS, PS and ES use the key box. Verify checks the token. Generate reads the header and payload boxes.
A JWT is three Base64url parts: header, payload, signature. The header and payload are JSON, and they are not encrypted. Anyone with the token can read them. The signature shows the payload was not edited, if you have the HMAC secret or the public key. This page decodes, verifies and generates in the browser. It flags alg none, a missing or due exp, a time written in milliseconds, and an HMAC secret shorter than 32 bytes. The token is not uploaded. A checksum on the hash page is not a JWT signature. exp is a Unix time in seconds; other zones are on the Unix timestamp page.
exp is now or earlier, it is marked expired.{"sub":"user-1"} and sets HMAC secret to secret. Secret is Base64 stays off. Verify says the signature matches. Security audit says the secret is 6 bytes and that there is no exp. The sample is short on purpose.iat and exp alone. Choose 1 hour and Generate writes both as seconds from now. Template User fills sub 1234567890, name John Doe and email [email protected]. Template Access fills sub user-1 and scope read.HS256, HS384 and HS512 use the secret. A secret under 32 bytes still signs, and the audit warns. Tick Secret is Base64 only when the secret is Base64, not the raw text. RS256, RS384, RS512, PS256, PS384, PS512, ES256, ES384 and ES512 use a PEM or a JWK. A public key verifies. A PKCS#8 private key generates, and an RSA private key can also verify because the public half is inside it. Paste SPKI (BEGIN PUBLIC KEY), PKCS#8 (BEGIN PRIVATE KEY), or PKCS#1 RSA. A certificate is rejected. An EC key that says BEGIN EC PRIVATE KEY is rejected; export PKCS#8. alg none is never treated as valid. Verify follows the alg in the header. An HMAC secret is not used to check an RSA token. exp, nbf and iat are seconds. A 13-digit value is flagged, not converted. JWKS must be a set of keys, or one JWK. Several keys and no kid is an error. An array in Header or Payload blocks Generate.
sub and exp on a token you already hold.No. It is Base64url. Do not put a password, an id number or a card number in it.
The token needs two dots and two JSON parts. The header alg must be one this page knows. HS needs the same secret the signer used, and Secret is Base64 must match how that secret is stored. RSA and EC need the public key, not a certificate. A past exp is a warning in Security audit, not a failed signature.
HS256 is one shared secret. RS256 is a private key to sign and a public key to check. Do not hand the HMAC secret to another service. Hand them the public key.
The header says there is no signature. This page will not call that token valid.
No. Shorten exp on the server that issues tokens, or keep a block list there.
Checking stays in the browser. Verify with JWKS is the one request, and it downloads keys, not your token. Still do not paste a live production token on a shared computer. If the local time looks hours off, the number is UTC and the line under the payload is this computer’s clock.