JWT Generator
Create a signed JSON Web Token in the browser with HS256, HS384, or HS512, adding issued-at and expiry claims to the claim set you paste in.
How to use
- Paste your claims as a JSON object.
- Choose the algorithm and set the signing secret.
- Copy the token and the claims that were signed.
A JWT generator builds a JSON Web Token from a claims object and signs it with a secret using HMAC. Only the HMAC algorithms can be used here, because signing with a private key needs a key the browser is not meant to hold.
Paste or type something above.
Questions about jwt generator
- Why only HS256, HS384, and HS512?
- HMAC signs with a shared secret. Asymmetric algorithms need a private key, which belongs on a server rather than in a browser page.
- Is the secret safe in a browser page?
- The secret you type is used on your device and never sent. That still makes this a development tool, not a place to sign production tokens.
- What do exp and iat do?
- They are Unix seconds. iat records when the token was issued, and exp is when it stops being accepted.
Related tools
- JWT Decoder Read the header and claims of a JSON Web Token, see the algorithm, subject, issued time, a...
- JWT Secret Generator Create random signing secrets for JSON Web Tokens with a length, alphabet, and batch size...
- HMAC Generator Sign a message with a secret key using HMAC SHA-1, SHA-256, SHA-384, or SHA-512, and copy...