JWKS inspector

Inspect a JSON Web Key Set or a single JWK: key types, curves, RSA sizes, kid, use, alg and RFC 7638 thumbprints. Optionally match a token's kid against the set.

🔒 Keys are parsed locally and never uploaded.

JWK / JWKS inspector

Match a JWT's kid against this key set (optional)
🔒 Decoded locally — never sent anywhere.0 chars

What is a JWKS?

A JWK Set (RFC 7517 §5) is a JSON object with a keys array. Each entry is a JSON Web Key describing one public key. Identity providers publish their JWKS at a stable URL (the jwks_uri in the OpenID Connect discovery document) so APIs can verify tokens without sharing secrets.

{
  "keys": [
    {
      "kty": "RSA",
      "kid": "2026-09-a",
      "use": "sig",
      "alg": "RS256",
      "n": "sXch…",
      "e": "AQAB"
    }
  ]
}

Key members

MemberMeaning
ktyKey type: RSA, EC, OKP or oct (symmetric).
kidKey ID. Matched against the token header's kid to pick the verification key.
useIntended use: sig (signatures) or enc (encryption).
algAlgorithm the key is intended for. If present, verifiers should only use the key with that algorithm.
n, eRSA modulus and exponent (Base64URL).
crv, x, yEC curve and public point coordinates.
d, p, q, dp, dq, qiPrivate key material. These must never appear in a published JWKS — the inspector warns if they do.

Key rotation

To rotate keys safely, publish the new key in the JWKS before signing with it, keep the old key until every token it signed has expired, and give each key a unique kid. A kid that isn't in the set usually means the verifier's cached JWKS is stale or the token comes from another environment.

JWK thumbprints

RFC 7638 defines a canonical SHA-256 thumbprint over a key's required public members. It is a stable, standards-based way to derive a kid, and it lets you confirm that two JWKs describe the same key even when their optional members differ.

Ready to verify? Paste the token and JWKS into the JWT verifier. Need a key pair and JWKS for testing? Use the JWT key generator.