Vettero

JWT Verify

Verify a JSON web token signature and claims.

Type

crypto.jwt.verify
Block Tool Crypto
Folderbasic/crypto
Channels

Any

Pipe

Value

Scope

Any

JWT Verify checks the signature, pins Algorithm, and optionally checks audience, issuer, subject, JWT id, and time claims. Invalid tokens do not continue on the success outlet. JWT Decode does not replace this for authentication.

Configure

SettingDescription
TokenCompact JWT (required)
Key typePassphrase (HMAC) or PEM key
SecretHMAC secret when key type is passphrase
Public keyPEM public key when key type is PEM
AlgorithmMust match how the token was signed
AudienceExpected aud
IssuerExpected iss
SubjectExpected sub
JWT IDExpected jti
Clock tolerance (seconds)Slack for exp and nbf
Ignore expirationSkip the exp check
Ignore not beforeSkip the nbf check
Return additional infoOff: payload only. On: header, payload, and signature

Handles

HandleRole
In (target)Incoming connection
Out (source)Continues only when the token is valid
ErrorCatchable failures: missing token or key (MISSING_VALUE), or invalid signature, algorithm, or claims (JWT_INVALID)

Connect Branch errors to Error to split those codes.

Pipe schema

On success the pipe is the payload object. With Return additional info it is an object with header, payload, and signature.

Catch errors with a block Error outlet or Try.

Use case

  • Trust Authorization: Bearer … on an HTTP Server handler.
  • Check a token you minted with JWT Sign.
Copyright © 2026