Security Tools

JWT Security Checker

Audit a JSON Web Token without sending it anywhere. The checker decodes the header and payload in your browser and tests for the common JWT mistakes: unsigned tokens (alg none), HMAC tokens signed with well-known weak secrets (tested locally with Web Crypto), embedded keys and key URLs (jwk, jku, x5u), suspicious kid values, missing or very long expiry, missing issuer and audience, tokens issued in the future, and passwords or personal data in the payload.

  • Runs in your browser
  • No sign-up
  • Free to use

Everything runs in your browser – the token is never sent to our server. Prefer test tokens: a real token is a credential and may still be valid.

How to use JWT Security Checker

  1. Paste a JWT.
  2. Keep the weak-secret test on for HS tokens.
  3. Click Check token.
  4. Fix the issuer’s configuration.

JWT Security Checker features

Weak secret test

Common secrets, tested locally.

Header attacks

alg none, jwk, jku, x5u, kid.

Claim checks

exp, iat, iss, aud.

Payload review

Passwords and personal data.

Grade

Rule-based score.

Private

The token never leaves your browser.

When to use JWT Security Checker

  • API security reviews.
  • Debugging authentication.
  • Pen-test preparation.
  • Teaching token security.

JWT Security Checker FAQ

Is it safe to paste a token?

It is processed only in your browser, but a real token is a credential – prefer test tokens or expired ones.

Why is a weak secret so bad?

Anyone who guesses the secret can create valid tokens for any user.

Is a JWT payload encrypted?

No. It is Base64URL-encoded; anyone with the token can read it.

Which algorithm should I use?

ES256 or EdDSA for tokens verified by several services; HS256 only with a long random secret.

Tokens are credentials

Treat JWTs like passwords: short lifetimes, strict validation of algorithm, issuer and audience, and no secrets inside.

How it works: checks that need the network are made by our server through a guarded client that only connects to public addresses on the standard web ports, pins every connection to the validated address and limits time and response size. Pasted input is analysed in your browser and never sent. Nothing you check is stored, and requests are rate-limited to keep the service fair.

Every finding is rule-based and explained: the tool tells you what it saw, why it matters and what to change, instead of showing an unexplained score. Grades summarise the findings so you can compare sites and track progress after a fix, but the individual checks are what you should act on.

Only check systems you own or are authorised to assess. The probes behave like a normal browser or client – they read public responses and perform ordinary handshakes – and never try to exploit a weakness, guess passwords or overload a server.

Related tools on this site cover the rest of a security review – security header generators, CSP and CORS generators, SSL certificate and expiry checks, SPF, DKIM and DMARC record checkers, JWT tools and password generators – so you can fix what you find in the same place.

Who it is for: developers hardening a release, system administrators and DevOps teams, security and compliance reviewers preparing for audits such as PCI DSS or ISO 27001, and site owners who want to know whether their basics are right. No account or installation is needed.

Other useful tools