jwt_verify
Cryptographically verifies a JWT signature (HS256/384/512, RS/PS256/384/512, ES256/384/512) and checks exp/nbf claims. Provide a secret for HS*, or a JWK or JWKS URL for RS/PS/ES. Use instead of jwt_decode whenever authenticity matters.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| jwk | No | Public key in JWK format, for RS/PS/ES algorithms. | |
| token | Yes | The JWT to verify. Checks the cryptographic signature -- use /jwt-decode if you only need to read the header and payload. | |
| secret | No | Required for HS256/384/512. | |
| jwks_url | No | URL to a JWKS document; the key is matched by the token's "kid" header. |