What this does
A JSON Web Key (JWK, RFC 7517) describes a cryptographic key as JSON; a JWK Set (JWKS) is a list of them, typically published at /.well-known/jwks.json by an OAuth or OpenID Connect provider so clients can verify token signatures. Paste a key set to see each key in plain terms instead of reading Base64URL by eye.
What you see for every key
- Key type (
RSA,EC,OKP,oct), and the size in bits or the curve. use,alg,key_ops, andkid, with an explicit "not set" when missing.- Whether the entry carries private material. Public JWKS documents must never include
dor symmetric secrets. - The RFC 7638 JWK thumbprint (SHA-256 and SHA-1), computed from only the required members in lexicographic order, so it identifies the key regardless of formatting or extra fields.
Warnings
The viewer flags problems it can establish from the document alone: private or symmetric key material, RSA moduli under 2048 bits, alg: none, both use andkey_ops set, unknown use values, missing kid, duplicatekids, and empty sets. A broken entry shows its own error and does not hide the rest.
Fetching a JWKS
This page never makes a network request. To inspect a provider's keys, open its JWKS URL in a browser tab or run curl, copy the response, and paste it here. Convert a key to PEM with thePEM / JWK converter, or decode a token that references it with the JWT decoder.
Privacy
Everything is parsed in your browser and held in memory only. If you paste a private JWK, it is not uploaded or saved.