About this utility
How to use JWT HS256 Verifier
Verify an HS256 signature and inspect the decoded claims locally.
What to provide
Paste an HS256 compact JWT.
Secrets are used only for the current run and are never stored or transmitted.
- Paste, type, or drag and drop a supported text file into the input area.
- Place the second value in the adjacent panel. Sensitive fields are masked by default.
- Review the input and the clearly labeled output behavior.
- Select “Run tool” or press Ctrl/Command + Enter, then copy, download, or move the result back into the first input for another pass.
Use “Swap inputs” to reverse the comparison without copying either value.
What the result means
Signature status plus decoded header and payload.
Privacy and safety
This utility is loaded as browser code and processes your input only in this tab. OmniCastConverter has no upload endpoint and never stores your content, filenames, tokens, or secrets. Generated markup and code are shown as inert text and are never executed.
Limitations
- Signature validity does not validate issuer, audience, expiry, revocation, or authorization policy.
Try the included example
Select “Load example” at any time to restore this tested sample.
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiJ1c2VyLTcifQ.pQqVw6ErKllHM3ZziL7gL1J3RrmP7S3T9tRrbNWqc6ssecret