JWKS Viewer
Inspect JWKS documents, export public PEM, and build a public JWKS from SPKI keys — entirely in your browser.
Last updated August 26, 2026
Prove it runs locally
- Open DevTools → Network tab
- Click Generate
- Confirm zero outbound requests for the secret
Generation uses crypto.getRandomValues() in your browser. Privacy policy
How to Use This Tool
Paste a JWKS document ({ "keys": [...] }) or a single JWK into View mode — or click Load sample — then Inspect keys. Review kid, kty, alg, use, and size or curve for each entry.
If a key includes private fields (d, p, q, …), treat it as secret material. Use Copy public-only before publishing; never ship private JWKs on a public JWKS endpoint.
For RSA or EC public keys, click Export public PEM to convert the JWK to SPKI PEM for libraries that prefer PEM files.
Switch to Build mode, paste an SPKI public PEM (from the RSA Key Generator or your issuer), set kid/alg/use, and add keys to assemble a JWKS JSON document you can copy. Mismatched alg (e.g. RS256 on an EC key) is corrected automatically.
This tool does not fetch remote JWKS URLs. Paste JSON only so key material stays in your browser. Sample keys are ephemeral demos, not production signing material.