JWT Verify Online — 14 Algorithms vs JWKS, PEM & Claims
Verify JWT signatures and optional exp/aud/iss claims in your browser. Live verify against pasted JWKS/JWK, public PEM, or HMAC secret — same algorithm set as jwt-encode/decode. Encode · Decode · Verify tabs. Paste-only — no remote JWKS fetch. Signature verify ≠ authorization.
Developer notes
• Paste compact JWT first — trust material tabs follow the header alg. • Algorithms: HS256/384/512, RS256/384/512, PS256/384/512, ES256/384/512, EdDSA (same as jwt-encode/decode). `alg: none` is rejected. • jwt-decode inline verify checks signature only; this tool adds exp/nbf/aud/iss policy. • verify ≠ trust or authorization. • Copy result never includes raw private JWKS material. • 512 KB per field.
Options
When teams pick this route
• Debug API auth with a JWKS from provider docs. • Check exp/aud/iss after jwt-decode. • Validate test tokens from jwt-encode fixtures (any supported alg).
Worked examples
RS256 JWT + matching JWKS
JWT
Result
documentation.securityTools.jwtVerify.examples.two.title
JWT
Result
Related tools
Same JWT family: jwt-encode · jwt-decode. Inspect keys: inspect-jwks · pem-jwk-converter.
JWT verify FAQ
Paste-only verify
Can I paste a JWKS URL?
No. Paste the JSON body of the JWKS — nothing is fetched from the network.
Does verify mean the user is trusted?
No. This checks signature and optional claims only — not authorization or identity provider trust.
When should I use jwt-decode?
Use jwt-decode to read header/payload and optionally check signature inline. Use this tool for JWKS/PEM trust material and exp/aud/iss policy.
Which algorithms are supported?
Same 14 signing algorithms as jwt-encode/decode: HS256/384/512, RS256/384/512, PS256/384/512, ES256/384/512, and EdDSA. Unsecured alg:none is rejected.
Can I use a public PEM instead of JWKS?
Yes — use the Public PEM tab for SPKI or X.509 certificate PEM when you have a single asymmetric key.
Security & tokens
JWKS, X.509 certificates, and secrets scan — browser-local.
Explore other tool categories
Minify
Shrink code and assets for production — minify JavaScript, CSS, HTML, JSON and XML before gzip or CDN deploy.
Beautify
Make code readable with consistent indentation — beautify JavaScript, CSS, TypeScript, SCSS, LESS, Markdown, GraphQL, SQL, YAML and more in your browser.
Unminify
Expand minified or compressed code — unminify JavaScript, CSS, TypeScript, SCSS, LESS, SQL, YAML and other formats when debugging or reviewing.
Conversion
Transform data between JSON, YAML, XML and CSV locally — no server uploads.
CSS preprocessors
Compile SCSS or LESS to standard CSS in the browser — pair with beautify or minify for a full stylesheet workflow.
JSON Tools
Validate, format, diff and explore JSON payloads — complementary to minifiers and converters.
SVG Tools
Preview, optimize with SVGO, export Data URI, resize, beautify, convert to JSX and validate SVG — all in your browser.
DevOps & Infra
Terraform HCL format/validate/minify, Dockerfile format & lint, Docker Compose and .env validation.
CI/CD
GitHub Actions and GitLab CI — format YAML and check workflow/job structure in your browser.
Logs & observability
Line-oriented JSON/NDJSON and Nginx/Apache access logs — format, filter, validate, and CSV/TSV.
Kubernetes
Multi-doc manifests, structural validate, Ingress/Deployment starters, and Helm values formatting.
Networking / IP
CIDR, subnets, and IPv4/IPv6 helpers — in your browser.
API & schemas
OpenAPI tools to format, validate, and lint your specs.
Encoding
Encode or decode Base64, URL components and HTML entities — client-side only.
Developer utilities
Timestamps, UUID, ULID, Nanoid, cron, passwords, regex, slugify, number bases, case, text diff, and chmod — all client-side.
Text & Markdown
Count words, build Markdown TOCs, and clean line lists — all in your browser.
AI & LLM
Token counting, pricing estimates, and context-window fit — 100% browser-local.
Serialization
Serialize and deserialize PHP data structures beside JSON workflows.