JWT Signature Validator

Verify HMAC-signed JWTs and inspect important claims without sending the token or secret to a server.

Browser onlyHS256 / HS384 / HS512Claim validation

Signed JWT

Verification settings

Validation result

Enter a JWT and its signing secret

The signature and time-based claims will be checked automatically.

Authentication

A decoded token is not necessarily trustworthy

JWT validation must verify the signature and enforce application-specific claim requirements.

Signature verification

The signature confirms that the protected header and payload match the supplied signing secret. Changing either section invalidates the signature.

Claim verification

Applications should also validate expiration, activation time, issuer, audience, and any required authorization claims.

Guide

About JWT Signature Validator

JWT validation confirms that protected token data matches a signature produced with the expected key.

This tool verifies HMAC-signed JWTs using HS256, HS384, or HS512 and helps review important claims.

A valid signature alone is not enough; applications must also validate issuer, audience, time claims, and authorization rules.

Supported verification algorithms

This validator supports shared-secret HMAC algorithms.

  • HS256
  • HS384
  • HS512
  • Local Web Crypto verification

Signature verification

Verification recomputes the HMAC over the encoded header and payload and compares it with the supplied signature.

Claim validation

After signature verification, enforce expected issuer, audience, expiration, not-before, and application-specific claims.

Secret safety

HMAC secrets allow both signing and verification. They must remain confidential and should be strong, random, and rotated appropriately.

FAQ

Frequently asked questions

What is the difference between decoding and validation?

Decoding reads token data; validation checks the signature and required claims.

Which algorithms are supported?

HS256, HS384, and HS512.

Why is the HMAC secret required?

The same secret is used to create and verify HMAC signatures.

Does a valid signature mean the token is authorized?

No. Authorization and claim requirements must still be enforced.

Why might verification fail?

The secret, token bytes, algorithm, or signature may not match.

Are the token and secret uploaded?

Verification is intended to occur locally in your browser.

Continue exploring

Useful tools for the next step in the same workflow.