TsWorks Tools
All tools (39)

JWT Generator

Sign a JSON Web Token in your browser with HMAC, RSA or ECDSA.

Algorithm
Expires

Signing uses WebCrypto in this tab. Keys and tokens are never sent anywhere, and nothing is stored when you close the page.

Sign a JWT in your browser

Set the claims, pick an algorithm, supply a key, and get a signed token. Signing uses WebCrypto in this tab - the key and the token are never transmitted, which is the difference between a test token and a leaked credential.

Picking an algorithm

  • HS256 and its siblings use one shared secret to both sign and verify. Simple, and fine when the same service does both. Anyone who can verify can also forge.
  • RS256 and PS256 use an RSA key pair: you sign with the private key and publish the public one. RS256 is what most identity providers issue; PS256 is the newer RSA-PSS padding and is preferred for new systems.
  • ES256 uses an ECDSA P-256 key pair. Much shorter signatures than RSA for equivalent strength, which keeps tokens small.

For the asymmetric algorithms, Generate key paircreates one here and shows you both halves. The private key is filled in for signing; the public key is what you give to whoever verifies.

Claims worth setting

  • sub - who the token is about.
  • iss and aud - who issued it and who is meant to accept it. A verifier that does not check aud will accept a token minted for a different service.
  • exp - set from the Expires control. Short is safer; a JWT cannot be revoked once issued, so the expiry is your only lever.
  • iat and jti - when it was issued, and a unique id if you need replay detection.

A note on secrets

An HS256 secret should be at least 256 bits of real randomness. Short, guessable secrets are brute-forced offline in seconds - the attacker has the token, and checking a candidate secret is one HMAC. Tokens signed here are for development and testing; generate production keys with your own tooling and keep them out of a browser.

Related tools