JWS Signature Verifier

Verify a compact RS256 or ES256 JWS against a separately supplied public key and inspect explicit claim-policy checks.

Inputs stay on your device No sign-up Free to use
How this works

The tool runs in this browser. Your file or text is not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.

Privacy details

Verify JWS controls

The three dot-separated parts: protected header, payload and signature. RS256 and ES256 are supported. A token that declares "none", an HMAC algorithm, "crit" or "b64":false is refused.

Paste the public key you already trust, as a JWK or a JWKS. The key is never taken from the token, and embedded keys (jwk, jku, x5u) are refused.

The algorithm you require. It must match the token header and, when the key declares one, the key "alg". A mismatch is refused rather than tried.

The instant used for exp and nbf checks, written as YYYY-MM-DDTHH:MM:SSZ. Leave it blank to use the current time in this browser.

A whole number of seconds added to both sides of exp and nbf checks, for tokens issued or read by a clock that is slightly off. From 0 to 300 seconds. Zero means an exact comparison.

The exact "iss" value you require. Leave it blank to skip the issuer check.

The exact "aud" value or a value inside an "aud" array. Leave it blank to skip the audience check.

Processed in your browser. Your inputs stay on this device.

Showing a generated example. Generate again for a new result.

How to use JWS Signature Verifier

  1. Supply the compact jws and trusted public jwk (supplied separately) using the supported input described beside the controls.
  2. Review the selected options and the declared scope, then run the jws signature verifier.
  3. Read the result and unresolved findings before downloading or sharing a report. The original input is not changed.

Example: JWS Signature Verifier

Verify a supported signed token against an explicitly supplied trusted public key. This example uses synthetic public data.

You add
Compact JWS: eyJhbGciOiJFUzI1NiIsImtpZCI6InN5bnRoZXRpYy1kZW1vIiwidHlwIjoiSldUIn0.eyJpc3MiOiJodHRwczovL2lzc3Vlci5leGFtcGxlIiwic3ViIjoic3ludGhldGljLWRlbW8iLCJhdWQiOiJkZW1vLWFwaSIsImV4cCI6MjAwMDAwMDA2MCwibmJmIjoxMDAwMDAwMDAwfQ.kC9lwjNNvVd30Ql3ET2lK7GAshz0Rig2VMmbS0fNE5yTcGYfzoTGeHEGj-aq_pTtBBuCVmAg0cBjVQiWkkx7Ng Trusted public JWK (supplied separately): {"kty":"EC","x":"423IsUaZ4rkzM4DqGWlqrY5kTtS2bQ6YkWGPS4Iq2hw","y":"-nrnuCEOId4KxhLZr-CilOx0k5cvNbg9_-rIdipuCNQ","crv":"P-256","alg":"ES256","kid":"synthetic-demo","use":"sig","key_ops":["verify"]} Expected algorithm: ES256 Review time (UTC): 2033-05-18T03:33:20Z Clock tolerance (seconds): 0 Expected issuer (optional): https://issuer.example Expected audience (optional): demo-api
You get
Signature is valid for the supplied public key. 0 policy observation(s) need attention. Algorithm (expected and header) | ES256 | Signature | Valid | Signing input bytes | 210 |

Options

Expected algorithm
Choose the algorithm independently of the token. The header, selected algorithm and key type must agree.
Claim policy
Enter only the issuer, audience and review-time rules relevant to your application. An omitted policy is not a passed identity check.

Supported inputs and limits

Compact JWS only; supported public-key algorithms and keys only. No signing, remote key lookup, embedded-key trust, complete JWT validation or replay prevention.

Where your input is processed

This tool processes your input in this browser. Your text and files are not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.

Signature and claims answer different questions

A matching signature shows that the exact signing bytes verify against the supplied key. You must establish why that key is trusted. Issuer, audience and time observations are separate checks under your entered policy; a signature alone does not authenticate a person or prevent token replay.

Questions about JWS Signature Verifier

Does a matching signature prove identity?

Only the cryptographic match against your supplied key is checked. Identity and application authorization require independently established trust and policy.

Can it verify an unsigned or HMAC token?

No. This verifier accepts only its supported public-key signature algorithms and refuses unsigned or shared-secret modes.

Are token URLs fetched?

No. The page does not discover keys or contact an issuer. Supply the public key separately.

Project manager: Tony Hines · Content updated 4 October 2026 · Report a problem