Task path / input to outcome
How to decode, sign, and verify a JWT
- 01
Pick the operation
Choose Decode to inspect untrusted claims, Sign to create a token, or Verify to check a token with your selected algorithm and key.
- 02
Paste the token or write the payload
For Decode and Verify, paste the compact three-segment token into Compact JWT, up to 64 KiB. For Sign, write the claims as a JSON object in JSON payload, up to 32 KiB; anything that is not a JSON object is refused.
- 03
Load a sample to explore
Press Load sample to see the full workflow with safe material: Decode gets a readable HS256 token, HMAC modes get a demonstration token with its secret, and asymmetric modes load a payload so you can paste your own matching key.
- 04
Select the algorithm and key
In Sign and Verify, choose an Algorithm from the HMAC, RSA, or ECDSA groups. HS algorithms take a Shared secret of at least 32 UTF-8 bytes for HS256 (48 for HS384, 64 for HS512); RS and ES take a PEM-encoded PKCS8 private key for signing or an SPKI public key for verification, up to 16 KiB.
- 05
Run and read the verdict
Run the selected operation. Decode displays untrusted header and payload data; Sign produces a compact token. Verify checks the signature and any exp/nbf conditions at the displayed browser time. Read the time cards and specific failure message, then correct the input and run again.
- 06
Copy, download, and clean up
Copy result puts the token or decoded JSON on the clipboard, and Download saves toolars-jwt.txt or toolars-jwt.json. Keys live in memory only: switching modes or algorithms clears the key field, and Reset empties everything.