How to use Public JWK and JWKS Inspector
- Supply the public jwk or jwks and public export format using the supported input described beside the controls.
- Review the selected options and the declared scope, then run the public jwk and jwks inspector.
- Read the result and unresolved findings before downloading or sharing a report. The original input is not changed.
Example: Public JWK and JWKS Inspector
Inspect public JSON keys, compute standard thumbprints and convert supported public formats. This example uses synthetic public data.
Options
- Key or key set
- Supply a public JWK or bounded JWKS. Private and symmetric key material is refused rather than removed for you.
- Key metadata
- Algorithm, use and operation declarations can constrain verification. A key identifier is a label and may be duplicated, so inspect the full inventory.
Supported inputs and limits
Where your input is processed
This tool processes your input in this browser. Your text and files are not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.
A thumbprint identifies key material
The thumbprint uses the required public members in their defined canonical order. Optional identifiers and descriptive metadata do not establish who owns the key. Keep the fingerprint with the independent source from which you obtained the public key; a correctly formed key can still be untrusted.
Questions about Public JWK and JWKS Inspector
Does changing kid change the thumbprint?
The thumbprint covers the required public key members, not the optional kid label.
Can I paste a private JWK?
No. Private and symmetric material is refused. Export a public key in the originating application first.
Does public export establish trust?
No. It changes or records the public representation; it does not authenticate its source.