JWT Secret Generator

Create random signing secrets for JSON Web Tokens with a length, alphabet, and batch size you choose, plus the estimated entropy of each secret.

A JWT secret generator produces random strings for signing JSON Web Tokens. The length and alphabet decide how much randomness each secret carries, and the tool reports that figure so you can judge it.

Output

                

Paste or type something above.

Questions about jwt secret generator

How long should a JWT secret be?
At least 32 characters from a full alphabet, which is the minimum recommended for HS256. Longer is better when you can store it safely.
Where should I keep the secret?
In an environment variable or a secret manager, never in source control or a client-side bundle.
Is the secret ever sent anywhere?
No. It is generated on your device and stays in the page until you leave it.