Only workspace IDs are saved in this browser—never files or input.
LOCAL TOOL / SECURITY

JWT RSA & ECDSA Verifier

Paste a compact JWT whose alg is supported by WebCrypto.

Paste, type, or drag & drop a text file 89 chars · 1 lines · 89 B

Paste only the public verification key. Key material is used in memory and never persisted.

Options
Optional exact iss claim.
Optional aud value to require.
Allowed clock skew in seconds.
Runs locally in this browserNothing is uploaded. Passwords are stored only when you explicitly choose Remember on this device.
02
Tool outputSignature status, decoded claims, expiry, issuer, and audience policy results.
Run toolNothing is uploaded. Passwords are stored only when you explicitly choose Remember on this device.
About this utility

How to use JWT RSA & ECDSA Verifier

Verify RS256/384/512 or ES256/384 JWT signatures with a local JWK or PEM public key and inspect claim policy.

What to provide

Paste a compact JWT whose alg is supported by WebCrypto.

Paste only the public verification key. Key material is used in memory and never persisted.

  1. Paste, type, or drag and drop a supported text file into the input area.
  2. Place the second value or file in the adjacent panel. Sensitive fields are masked by default.
  3. Choose the options that match your intended result.
  4. Select “Run tool” or press Ctrl/Command + Enter, then copy, download, or move the result back into the first input for another pass.

Use “Swap inputs” to reverse the comparison without copying either value.

What the result means

Signature status, decoded claims, expiry, issuer, and audience policy results.

Privacy and safety

This utility is loaded as browser code and processes your input only in this tab. OmniCastConverter has no upload endpoint and never stores your content, filenames, tokens, or secrets. Generated markup and code are shown as inert text and are never executed.

Limitations

  • The example intentionally has an invalid signature. Trust, revocation, key rotation, and authorization remain application responsibilities.

Try the included example

Select “Load example” at any time to restore this tested sample.

eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiJ1c2VyLTciLCJleHAiOjIwMDAwMDAwMDB9.invalid
{"kty":"RSA","n":"sXchDaQebHnPiGvyDOAT4saGEUetSyoe3A4JMaD-WxS7dN5YQnO7F_YWA8mI9K-T5nTqa1cM9E1z_1N2Q","e":"AQAB","alg":"RS256"}