All tools (39)
JWT Generator
Sign a JSON Web Token in your browser with HMAC, RSA or ECDSA.
Signing uses WebCrypto in this tab. Keys and tokens are never sent anywhere, and nothing is stored when you close the page.
Sign a JWT in your browser
Set the claims, pick an algorithm, supply a key, and get a signed token. Signing uses WebCrypto in this tab - the key and the token are never transmitted, which is the difference between a test token and a leaked credential.
Picking an algorithm
- HS256 and its siblings use one shared secret to both sign and verify. Simple, and fine when the same service does both. Anyone who can verify can also forge.
- RS256 and PS256 use an RSA key pair: you sign with the private key and publish the public one. RS256 is what most identity providers issue; PS256 is the newer RSA-PSS padding and is preferred for new systems.
- ES256 uses an ECDSA P-256 key pair. Much shorter signatures than RSA for equivalent strength, which keeps tokens small.
For the asymmetric algorithms, Generate key paircreates one here and shows you both halves. The private key is filled in for signing; the public key is what you give to whoever verifies.
Claims worth setting
sub- who the token is about.issandaud- who issued it and who is meant to accept it. A verifier that does not checkaudwill accept a token minted for a different service.exp- set from the Expires control. Short is safer; a JWT cannot be revoked once issued, so the expiry is your only lever.iatandjti- when it was issued, and a unique id if you need replay detection.
A note on secrets
An HS256 secret should be at least 256 bits of real randomness. Short, guessable secrets are brute-forced offline in seconds - the attacker has the token, and checking a candidate secret is one HMAC. Tokens signed here are for development and testing; generate production keys with your own tooling and keep them out of a browser.
Related tools
- JWT Decoder - decode and verify a token.
- JSON Formatter - build the claims payload.