Prove token integrity
Signature verification confirms that the signed header and payload have not changed and match the supplied HMAC secret.
Core transformations run locally in your browser.
Verify HS256, HS384, and HS512 JWT signatures locally with the expected shared secret.
Verify HMAC JWT signatures with the expected shared secret.
A valid signature does not automatically validate expiration, issuer, audience, or application authorization.
Signature verification confirms that the signed header and payload have not changed and match the supplied HMAC secret.
Applications must still enforce expiration, issuer, audience, nonce, and authorization requirements after checking a signature.