JWT Debugger
Verify signature, inspect claims, and sign JSON Web Tokens securely.
All processing is done locally in your browser.
Used to sign the generated token
Generated Token
Signed JWT
Resulting token will appear here...
Verify Integrity
Instantly check if a token has been tampered with by verifying its signature against a secret.
Deep Inspection
Decode headers and payload sections to see raw claims and metadata in a structured format.
Secure Signing
Create new tokens for testing using standard algorithms like HS256 with zero server tracking.
Understanding JWT Verification
The signature part of a JWT (the third part of the string) is what makes it secure. It is created by hashing the header and payload with a secret key. If even a single character in the payload is changed, the signature will no longer match, allowing the receiver to reject the token.
Verification Steps
- Decode: Extract header and claims to read data.
- Verify: Re-hash the data with the secret key.
- Compare: Ensure the generated hash matches the signature.
Algorithms Supported
HS256 (HMAC + SHA-256)
HS384 (HMAC + SHA-384)
HS512 (HMAC + SHA-512)