JWT Signature Validator
Verify HMAC-signed JWTs and inspect important claims without sending the token or secret to a server.
Signed JWT
Verification settings
Validation result
Enter a JWT and its signing secret
The signature and time-based claims will be checked automatically.
Authentication
A decoded token is not necessarily trustworthy
JWT validation must verify the signature and enforce application-specific claim requirements.
Signature verification
The signature confirms that the protected header and payload match the supplied signing secret. Changing either section invalidates the signature.
Claim verification
Applications should also validate expiration, activation time, issuer, audience, and any required authorization claims.
Guide
About JWT Signature Validator
JWT validation confirms that protected token data matches a signature produced with the expected key.
This tool verifies HMAC-signed JWTs using HS256, HS384, or HS512 and helps review important claims.
A valid signature alone is not enough; applications must also validate issuer, audience, time claims, and authorization rules.
Supported verification algorithms
This validator supports shared-secret HMAC algorithms.
- HS256
- HS384
- HS512
- Local Web Crypto verification
Signature verification
Verification recomputes the HMAC over the encoded header and payload and compares it with the supplied signature.
Claim validation
After signature verification, enforce expected issuer, audience, expiration, not-before, and application-specific claims.
Secret safety
HMAC secrets allow both signing and verification. They must remain confidential and should be strong, random, and rotated appropriately.
FAQ
Frequently asked questions
What is the difference between decoding and validation?
Decoding reads token data; validation checks the signature and required claims.
Which algorithms are supported?
HS256, HS384, and HS512.
Why is the HMAC secret required?
The same secret is used to create and verify HMAC signatures.
Does a valid signature mean the token is authorized?
No. Authorization and claim requirements must still be enforced.
Why might verification fail?
The secret, token bytes, algorithm, or signature may not match.
Are the token and secret uploaded?
Verification is intended to occur locally in your browser.
Continue exploring
Related tools
Useful tools for the next step in the same workflow.
JWT Decoder
Decode JWT headers and claims locally without uploading the token.
Authentication
JWT Inspector
Inspect JWT claims, expiration, lifetime, and common structural security issues.
Security Tools
HMAC Generator
Generate and verify keyed message authentication codes.
Cryptography
JWK & JWKS Inspector
Inspect JSON Web Keys, review JWKS collections, and generate RFC 7638 thumbprints.
PKI & Certificates
TOTP Generator
Generate and verify time-based two-factor authentication codes.
Authentication
Secure Password Generator
Generate strong random passwords locally in your browser.
Authentication