How to use JWS Signature Verifier
- Supply the compact jws and trusted public jwk (supplied separately) using the supported input described beside the controls.
- Review the selected options and the declared scope, then run the jws signature verifier.
- Read the result and unresolved findings before downloading or sharing a report. The original input is not changed.
Example: JWS Signature Verifier
Verify a supported signed token against an explicitly supplied trusted public key. This example uses synthetic public data.
Options
- Expected algorithm
- Choose the algorithm independently of the token. The header, selected algorithm and key type must agree.
- Claim policy
- Enter only the issuer, audience and review-time rules relevant to your application. An omitted policy is not a passed identity check.
Supported inputs and limits
Where your input is processed
This tool processes your input in this browser. Your text and files are not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.
Signature and claims answer different questions
A matching signature shows that the exact signing bytes verify against the supplied key. You must establish why that key is trusted. Issuer, audience and time observations are separate checks under your entered policy; a signature alone does not authenticate a person or prevent token replay.
Questions about JWS Signature Verifier
Does a matching signature prove identity?
Only the cryptographic match against your supplied key is checked. Identity and application authorization require independently established trust and policy.
Can it verify an unsigned or HMAC token?
No. This verifier accepts only its supported public-key signature algorithms and refuses unsigned or shared-secret modes.
Are token URLs fetched?
No. The page does not discover keys or contact an issuer. Supply the public key separately.