JWT Decoder
Decodes JSON Web Tokens, explains the claims, and verifies HS, RS, PS, and ES signatures.
Generate a 2048, 3072, or 4096-bit RSA key pair in your browser. You get the private and public key as PEM, the public key in OpenSSH format, and both as JWK.
The key pair is created by your browser's Web Crypto API (crypto.subtle.generateKey) with the public exponent 65537, then exported:
-----BEGIN PRIVATE KEY-----).-----BEGIN PUBLIC KEY-----), the format OpenSSL, Java, and most JWT libraries read.ssh-rsa wire format built from the key's modulus n and exponent e, ready for ~/.ssh/authorized_keys. The fingerprint is the SHA-256 of that blob, the same value ssh-keygen -lf prints.The purpose is stored with the key: a signing key can't be used for encryption in Web Crypto and the other way round, but the PEM files work anywhere.
ssh-rsa AAAAB3NzaC1yc2EAAAADAQAB. The AQAB part is the exponent 65537.openssl pkey -in private-key.pem -noout -text shows Private-Key: (2048 bit, 2 primes).| Size | Security (approx.) | Use |
|---|---|---|
| 2048 bits | 112-bit | Minimum today; fine for most TLS, JWT, and SSH keys until about 2030 |
| 3072 bits | 128-bit | Recommended for keys meant to last past 2030 |
| 4096 bits | about 140-bit | Long-lived keys; slower to generate and use |
openssl pkcs8 -topk8 or ssh-keygen -p.The keys come from the browser's cryptographic random generator and never leave the page. For keys that protect production systems, many teams still prefer generating them on the server itself.
Both hold the same public key. PEM (BEGIN PUBLIC KEY) is used by OpenSSL and most libraries; the OpenSSH line (ssh-rsa AAAA...) is what goes into authorized_keys.
Yes. Choose a signing purpose, then use the private PEM to sign and the public PEM or JWK to verify RS256 or PS256 tokens.
No. The key exists only in this page until you close it. Download it before you leave.
Often used together with the RSA Key Generator.
Decodes JSON Web Tokens, explains the claims, and verifies HS, RS, PS, and ES signatures.
Signs text or files with HMAC-SHA256 and other hashes, and checks signatures.
Generates secure random tokens and API keys with a chosen length, alphabet, and prefix.