2 All Tools⌘Kquick search

Crypto Β· JWT & Token

Debug APIs, clean content, format data, and run release checks directly in your browser.

Focused on JWT & Token with 2 tools. Use search to narrow down quickly.

⌘K

Separate reading a JWT from trusting it

A readable payload is a claim made by the token, not proof of its sender. Use generation for disposable fixtures, decoding for inspection and verification for the expected signing method and key.

Build a controlled test fixture

Choose test claims and a signing setup compatible with the verifier. A generated token is not automatically accepted by any real service.

A tamper check for a disposable token

1. Sign a test payload {"sub":"demo"}.
2. Verify with the corresponding trusted test key.
3. Change sub to "admin" without signing again.
4. Verification must fail.

A decoder may still display both payloads. The verifier must reject the modified signature input. Also test an incorrect key; successful decoding cannot replace either test.

Signature validity alone does not grant a permission or prove the token is unexpired, intended for this service, or not revoked.