Inspect JWKS / JWK — Pretty & Inventory

Inspect a JWK or JWKS in your browser. Pretty-print with private fields redacted, or list key inventory. Paste-only — no remote fetch, no JWT verify.

…
JWKS / JWK inspector — browser-local
Inspect a pasted JWK or JWKS document. Private fields (d, RSA factors, oct k) are redacted in output and copy.

Developer notes

Accepts a single JWK (kty) or a JWKS (keys). Pretty (redacted) = clone with private fields removed; Copy on Result uses that safe output. Inventory (metadata) never prints d/k/RSA factors. No JWT signature verification here — use <a href="/en/jwt-verify">jwt-verify</a>. No JWKS URL fetch. 512 KB limit.

Options

View
Pretty (redacted) = indented JSON without private fields; Inventory (metadata) = kid/kty/alg/hasPrivate only.
Sort keys
Orders JSON keys stably for reproducible diffs.

When teams pick this route

Review a JWKS before committing it. Check kid/kty/alg without exposing private key material. Spot public keys vs private material (hasPrivate warning).

Worked examples

Minified JWKS with private d → pretty (redacted)

Before

{"keys":[{"kid":"signing","kty":"RSA","use":"sig","alg":"RS256","n":"sXch8examplePublicModulusValueForDemoOnlyNotARealKey","e":"AQAB","d":"demo-private-exponent-removed-in-output"},{"kid":"verify","kty":"EC","crv":"P-256","x":"MKBAXEBexamplePublicXCoord","y":"4vVexamplePublicYCoord","alg":"ES256"}]}

After

{ "keys": [ { "kid": "signing", "kty": "RSA", "use": "sig", "alg": "RS256", "n": "sXch8examplePublicModulusValueForDemoOnlyNotARealKey", "e": "AQAB" }, { "kid": "verify", "kty": "EC", "crv": "P-256", "x": "MKBAXEBexamplePublicXCoord", "y": "4vVexamplePublicYCoord", "alg": "ES256" } ] }

Same paste → inventory metadata

Before

{"keys":[{"kid":"signing","kty":"RSA","use":"sig","alg":"RS256","n":"sXch8examplePublicModulusValueForDemoOnlyNotARealKey","e":"AQAB","d":"demo-private-exponent-removed-in-output"},{"kid":"verify","kty":"EC","crv":"P-256","x":"MKBAXEBexamplePublicXCoord","y":"4vVexamplePublicYCoord","alg":"ES256"}]}

After

[ { "kid": "signing", "kty": "RSA", "use": "sig", "alg": "RS256", "hasPrivate": true }, { "kid": "verify", "kty": "EC", "alg": "ES256", "crv": "P-256", "hasPrivate": false } ]

Related security tools

To decode a compact JWT use jwt-decode. To verify signatures use jwt-verify. Hub: security tools. Certificates: decode certificate.

Inspect JWKS FAQ

Local JWK / JWKS

When should I use jwt-decode instead?

Use jwt-decode for a compact JWT token (three segments). Use inspect-jwks for a JWK/JWKS JSON document (key sets), not for JWT payload claims.

Are private keys shown?

No. Private fields are stripped from pretty output and copy. A hasPrivate warning appears if they were present in the paste.

Can I fetch a JWKS URL?

No. Paste-only — nothing is fetched from the network.

Does it verify JWT signatures?

No. This tool formats and inventories keys only. To verify a JWT signature against pasted JWKS or JWK, use jwt-verify.

JWKS, X.509 certificates, and secrets scan — browser-local.