JWK & JWKS Inspector
Inspect JSON Web Keys, detect private material, review JWKS collections, and generate RFC 7638 thumbprints without uploading keys.
JWK or JWKS input
JSON Web Keys
Inspect keys used for JWT and JOSE verification
JSON Web Keys represent cryptographic key material in a JSON format used by JWT, JWS, JWE, OAuth 2.0, and OpenID Connect systems.
What this tool inspects
Review key type, algorithm, intended use, key operations, identifiers, curve parameters, RSA values, symmetric key data, and the structure of JWKS collections.
Protect private material
Public JWKs are commonly published through JWKS endpoints. Private or symmetric key values should remain confidential and must not be included in public key sets, logs, or client-side application bundles.
Guide
About JWK and JWKS Inspector
JSON Web Keys represent cryptographic keys in a JSON structure used by JOSE, JWT, OAuth, and OpenID Connect systems.
This inspector explains JWK fields, reviews JWKS collections, detects private material, and calculates RFC 7638 thumbprints.
Public keys may be shared, but private and symmetric key values must remain confidential.
Supported key types
The inspector recognizes common JOSE key families.
- RSA keys
- Elliptic-curve keys
- OKP keys such as Ed25519
- Symmetric octet keys
- JWKS collections
Important JWK fields
kty identifies the key type, kid identifies a key, alg suggests an algorithm, use indicates a purpose, and key_ops lists operations.
RFC 7638 thumbprints
A JWK thumbprint hashes a canonical subset of required public members to produce a stable key identifier.
Private-material warning
RSA private parameters, EC private values, OKP private values, and symmetric k values must never be published in a public JWKS.
FAQ
Frequently asked questions
What is a JWK?
A JWK is a JSON representation of a cryptographic key.
What is a JWKS?
A JWKS is a JSON object containing an array of JWKs.
What does kid mean?
kid is a key identifier used to select a key, especially during rotation.
What is an RFC 7638 thumbprint?
It is a deterministic SHA-256 hash of canonical required public JWK members.
Can a JWKS contain private keys?
It technically can, but public JWKS endpoints must never expose private or symmetric key material.
Are keys uploaded?
Inspection is intended to occur locally in your browser.
Continue exploring
Related tools
Useful tools for the next step in the same workflow.
JWK & JWKS Generator
Generate RSA, EC, or Ed25519 JWKs, JWKS, PEM keys, and RFC 7638 thumbprints locally.
PKI & Certificates
JWT Inspector
Inspect JWT claims, expiration, lifetime, and common structural security issues.
Security Tools
JWT Signature Verifier
Verify HMAC JWT signatures and important claims locally.
Authentication
Public & Private Key Analyzer
Identify PEM and OpenSSH key algorithms, formats, sizes, curves, and fingerprints locally.
PKI & Certificates
X.509 Certificate Decoder
Decode certificate identity, validity, algorithms, key details, and fingerprints locally.
PKI & Certificates
CSR Decoder
Decode PKCS#10 certificate signing requests and review requested identities, keys, and extensions.
PKI & Certificates