Stateless Tools

Header


      

Payload


      

JWKS 서명 검증

What to inspect first in a JWT

Start with the header algorithm

Check whether the alg value matches the algorithm your environment is supposed to use. A mismatch is a common source of failed verification.

Review time-based claims

exp, nbf, and iat should be interpreted alongside server clock differences. Time drift often looks like a token issue at first.

Check payload sensitivity

JWTs are only encoded, not encrypted. If the payload contains sensitive personal or secret values, the token design itself may need review.

Decoding is not the same as trust

Readable does not mean valid

Being able to decode a token only means you can inspect it. Trusting it still requires signature validation.

Why the JWKS step matters

In OIDC and external identity-provider setups, JWKS verification helps confirm that the token actually came from the issuer you expect.

Useful companion tools

JWT debugging often pairs well with JSON Formatter, the Base64 converter, and API Request Tester when you need to reproduce the full request flow.

What to check when verifying

Decoding is not verifying

The header and payload are Base64URL encoded, not encrypted, so anyone can read them. Reading the payload without checking the signature means trusting a token whose role an attacker changed to admin. A library's decode() does not verify.

Do not trust the header's alg

Attacks include switching alg to none and stripping the signature, or switching RS256 to HS256 so the public key is used as an HMAC secret. Pin the allowed algorithm in code — a token header is input, not configuration.

Keep secrets out of the payload

Since anyone can decode it, a token carrying national ID numbers, internal identifiers or detailed permissions is a disclosure by itself. A token in a server log is a usable credential until it expires.

More: step-by-step usage and worked examples

The order that makes JWT review easier

1. Open the header and payload first

Start by comparing alg, typ, iss, aud, sub, and exp against the environment you expect. That narrows the problem quickly.

2. Review time claims with a timestamp tool

Translate exp, nbf, and iat into human-readable time and account for server clock skew. The timestamp converter pairs well with this step.

3. Treat trust as a separate verification step

A readable token is not automatically a trustworthy one. When an external issuer is involved, use the JWKS URL to verify the signature explicitly.