Public JWK and JWKS Inspector

Inspect supported public JWK or JWKS keys, calculate SHA-256 thumbprints and export supported public key formats.

Inputs stay on your device No sign-up Free to use
How this works

The tool runs in this browser. Your file or text is not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.

Privacy details

Inspect public keys controls

One public JSON key, or a key set with a "keys" array of up to 20 keys. RSA keys need at least 2048 bits. Only public material is accepted: private fields (d, p, q, dp, dq, qi, oth) and symmetric keys (kty "oct") are refused.

The JSON inventory is always downloaded. Choosing PEM also downloads the public keys in the SPKI public-key format the browser can export.

Processed in your browser. Your inputs stay on this device.

Showing a generated example. Generate again for a new result.

How to use Public JWK and JWKS Inspector

  1. Supply the public jwk or jwks and public export format using the supported input described beside the controls.
  2. Review the selected options and the declared scope, then run the public jwk and jwks inspector.
  3. Read the result and unresolved findings before downloading or sharing a report. The original input is not changed.

Example: Public JWK and JWKS Inspector

Inspect public JSON keys, compute standard thumbprints and convert supported public formats. This example uses synthetic public data.

You add
Public JWK or JWKS: {"keys":[{"kty":"RSA","kid":"rsa-example","use":"sig","alg":"RS256","n":"wptZOlbQ2LTeMtre6H376rD0d7-WSlI7xGrE2XpIX6v2RdHgFSKJVnTx8cYfrdPAS4E-pOkrshHNFldrU8Dii4p6OLEDpMz78j597HVPjXYcO5csu-Mm6OHWrIi3inyI2cVlJvWRKrZaf96pL94_bRP7jUPHnG_wSCnF3mw7zKHeMJuGquSmOxYKtIMyvVj-oLf-issCDEhGv4OUCEp_50X7bOSoUqRlD5d7y-P6xl6k2pxBYgATD39aFW5vvqBQIOJ4iETlo451lYw6tfwHT3KdZx2s9JU3C-1ecozIZSrRPa5Ji70se5T8pTQhzC10YnQYqbKTlEB7TgK0XNkSOw","e":"AQAB"},{"kty":"EC","kid":"ec-example","use":"sig","alg":"ES256","crv":"P-256","x":"f83OJ3D2xF1Bg8vub9tLe1gHMzV76e8Tus9uPHvRVEU","y":"x_FEzRu9m36HLN_tue659LNpXW6pCyStikYjKIWI5a0"}]} Public export format: json
You get
Inspected 2 public keys. 1 | rsa-example | RSA public key | 2048 bits | sig | RS256 | E1N2DK6_CZG9ylKna-bCr-BOBdAF6-10ryEwGu9JVqM 2 | ec-example | EC public key | P-256 (256-bit field) | sig | ES256 | oKIywvGUpTVTyxMQ3bwIIeQUudfr_CkLMjCE19ECD-U

Options

Key or key set
Supply a public JWK or bounded JWKS. Private and symmetric key material is refused rather than removed for you.
Key metadata
Algorithm, use and operation declarations can constrain verification. A key identifier is a label and may be duplicated, so inspect the full inventory.

Supported inputs and limits

Supported public RSA and P-256 keys only; no private-key handling, ownership, certificate-chain trust or live JWKS refresh.

Where your input is processed

This tool processes your input in this browser. Your text and files are not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.

A thumbprint identifies key material

The thumbprint uses the required public members in their defined canonical order. Optional identifiers and descriptive metadata do not establish who owns the key. Keep the fingerprint with the independent source from which you obtained the public key; a correctly formed key can still be untrusted.

Questions about Public JWK and JWKS Inspector

Does changing kid change the thumbprint?

The thumbprint covers the required public key members, not the optional kid label.

Can I paste a private JWK?

No. Private and symmetric material is refused. Export a public key in the originating application first.

Does public export establish trust?

No. It changes or records the public representation; it does not authenticate its source.

Project manager: Tony Hines · Content updated 4 October 2026 · Report a problem