Build a controlled test fixture
Choose test claims and a signing setup compatible with the verifier. A generated token is not automatically accepted by any real service.
Debug APIs, clean content, format data, and run release checks directly in your browser.
Focused on JWT & Token with 2 tools. Use search to narrow down quickly.
Filter by Focus
A readable payload is a claim made by the token, not proof of its sender. Use generation for disposable fixtures, decoding for inspection and verification for the expected signing method and key.
Choose test claims and a signing setup compatible with the verifier. A generated token is not automatically accepted by any real service.
Use a trusted key and the algorithm your application expects. Then check issuer, audience and time requirements at the service boundary.
Inspect encoding and claims without treating the decoded content as authenticated.
1. Sign a test payload {"sub":"demo"}.
2. Verify with the corresponding trusted test key.
3. Change sub to "admin" without signing again.
4. Verification must fail.A decoder may still display both payloads. The verifier must reject the modified signature input. Also test an incorrect key; successful decoding cannot replace either test.
Signature validity alone does not grant a permission or prove the token is unexpired, intended for this service, or not revoked.