JWT signatures explained
The third segment of a JWT is a JSON Web Signature (RFC 7515). It is the only thing that makes the claims trustworthy — and it only does so once you have verified it with the right key.
What exactly is signed
The signature is computed over the ASCII bytes of the first two segments joined by a dot — the JWS signing input:
signing_input = base64url(header) + "." + base64url(payload)
signature = sign(alg, key, signing_input)
jwt = signing_input + "." + base64url(signature)Because the encoded strings are signed, not the parsed JSON, any change — reordering keys, adding whitespace, changing one character — produces a different signing input and the signature no longer matches. That is also why you cannot “fix” a claim in an existing token: you must sign a new one.
HMAC vs digital signatures
- HS256/384/512 compute an HMAC with a shared secret. The same secret signs and verifies, so every verifier could also mint tokens.
- RS*, PS*, ES* are asymmetric: a private key signs, the public key verifies. Verifiers can't create tokens, and public keys can be distributed freely via a JWKS.
Signature sizes are fixed by the algorithm: 32/48/64 bytes for HS256/384/512, the RSA modulus size (256 bytes for a 2048-bit key) for RS*/PS*, and 64/96/132 bytes for ES256/384/512.
Decoding is not verification
Any JWT decoder, including this one, can show you the claims without a key. An attacker can just as easily craft a token with "role": "admin". Only a successful verification with a key you trust — using an algorithm you chose, not the one the token claims — tells you the claims came from the issuer.
Debugging signature mismatches
- Confirm the algorithm in the header matches what the issuer uses.
- Check the kid and make sure you are using that exact key — issuers rotate keys.
- For HMAC, check the secret's encoding: raw text, Base64 or hex produce different key bytes.
- Make sure nothing re-serialized the token (URL-decoding, trimming, or copying only part of it).
- For ECDSA produced by custom code, ensure the signature is raw R||S, not DER.
Check a signature with a secret, public key, certificate, JWK or JWKS — locally in your browser.
Verify a signatureWant to see how a signature is produced? Sign a test token on JWTEncoder.com and inspect it here. Or read JWT security best practices.