How to use the JWT Generator
- Choose the signing algorithm.
- Edit the payload claims and set an expiry.
- Enter or generate a secret, then copy the signed token.
What does this tool do?
A JWT has three Base64URL parts: a header naming the algorithm, a payload of claims, and a signature. HMAC algorithms (HS256/384/512) sign with a shared secret that the server also knows.
Signing uses your browser's Web Crypto API, so the secret never leaves your device. Decode tokens with the JWT Decoder.
Why use it?
- HS256, HS384 and HS512.
- iat and exp claims added for you.
- Random secret generator.
Accuracy and limits
- For testing only. Don't paste production secrets into any website.
Privacy
The calculation happens instantly in your browser. The numbers you enter are not sent to our servers or saved. There's no account to create and nothing to install.
Last reviewed by the M2Toolkit team.