JWT Debugger

Verify signature, inspect claims, and sign JSON Web Tokens securely. All processing is done locally in your browser.

Used to sign the generated token

Generated Token

Signed JWT

Resulting token will appear here...

Verify Integrity

Instantly check if a token has been tampered with by verifying its signature against a secret.

Deep Inspection

Decode headers and payload sections to see raw claims and metadata in a structured format.

Secure Signing

Create new tokens for testing using standard algorithms like HS256 with zero server tracking.

Understanding JWT Verification

The signature part of a JWT (the third part of the string) is what makes it secure. It is created by hashing the header and payload with a secret key. If even a single character in the payload is changed, the signature will no longer match, allowing the receiver to reject the token.

Verification Steps

  • Decode: Extract header and claims to read data.
  • Verify: Re-hash the data with the secret key.
  • Compare: Ensure the generated hash matches the signature.

Algorithms Supported

HS256 (HMAC + SHA-256)
HS384 (HMAC + SHA-384)
HS512 (HMAC + SHA-512)