JWT Generator

Create a signed JSON Web Token in the browser with HS256, HS384, or HS512, adding issued-at and expiry claims to the claim set you paste in.

A JWT generator builds a JSON Web Token from a claims object and signs it with a secret using HMAC. Only the HMAC algorithms can be used here, because signing with a private key needs a key the browser is not meant to hold.

Output

                

Paste or type something above.

Questions about jwt generator

Why only HS256, HS384, and HS512?
HMAC signs with a shared secret. Asymmetric algorithms need a private key, which belongs on a server rather than in a browser page.
Is the secret safe in a browser page?
The secret you type is used on your device and never sent. That still makes this a development tool, not a place to sign production tokens.
What do exp and iat do?
They are Unix seconds. iat records when the token was issued, and exp is when it stops being accepted.