Developer Tools

JWT Generator

Build a signed JSON Web Token for testing an API or an authentication flow. Choose the algorithm, enter a test secret or private key (or generate one), fill in the standard claims and any custom claims, and the token is signed with the Web Crypto API on your device. The decoded header and payload are shown beside it, with warnings about weak secrets, missing expiry and sensitive data in the payload.

  • Runs in your browser
  • No sign-up
  • Free to use
Use test keys only. Everything runs in your browser and nothing is stored, but do not paste production secrets or private keys into any website.

Signing

Registered claims

Several: separate with spaces.

minutes

0 = no expiry

Custom claims

Header
Payload

How to use JWT Generator

  1. Choose an algorithm; HS256 needs a shared secret, the others a private key.
  2. Enter or generate a test secret or key pair.
  3. Fill in the claims and any custom JSON.
  4. Copy the token and test your API with it.

JWT Generator features

13 algorithms

HS256/384/512, RS256/384/512, PS256/384/512, ES256/384/512 and EdDSA.

Standard claims

iss, sub, aud, exp, iat, nbf and a random jti.

Custom claims

Any JSON object merged into the payload.

Test keys

Random secrets of the right length and fresh RSA, EC or Ed25519 key pairs.

Safety checks

Short secrets, tokens without expiry and secrets in the payload are flagged.

Local signing

Web Crypto in your browser; nothing is sent or stored.

When to use JWT Generator

  • Creating tokens to test an API that accepts JWT bearer tokens.
  • Reproducing a token with specific claims to debug authorisation rules.
  • Generating an RS256 key pair and token for a development environment.
  • Learning how JWT headers, payloads and signatures fit together.

JWT Generator FAQ

Is it safe to create tokens here?

The token is signed in your browser and nothing is transmitted or saved. Still, use test secrets and keys only: a production signing key should never be pasted into any web page.

Which algorithm should I use?

HS256 is simple when the same service issues and verifies tokens. RS256, PS256, ES256 or EdDSA suit setups where many services verify tokens, because they only need the public key.

How long should an HS256 secret be?

At least 32 random bytes (256 bits). Short or guessable secrets can be cracked offline from a single token. The Generate button creates a suitable one.

Is the payload encrypted?

No. A JWT is signed, not encrypted: anyone can decode the payload. Do not put passwords or private data in it.

Why is alg “none” not offered?

Unsigned tokens are a well-known source of security bugs. Verifiers should reject them, so this generator does not create them.

What key format is needed for RS256?

A PKCS#8 PEM private key (“BEGIN PRIVATE KEY”) or a private JWK. PKCS#1 keys can be converted with the openssl command shown in the error message.

How a JSON Web Token is built

A JSON Web Token consists of three parts separated by dots: a header, a payload and a signature. The header is a small JSON object naming the signing algorithm and type; the payload is a JSON object of claims about the user or client. Both are encoded with Base64URL, joined with a dot, and that string is signed. The signature, also Base64URL-encoded, becomes the third part.

Registered claims have agreed meanings. iss names who issued the token, sub whom it is about, aud which service should accept it, exp when it expires, nbf before when it is not valid, iat when it was issued and jti a unique identifier that allows detecting reuse. The times are NumericDates, whole seconds since 1 January 1970 in UTC. Verifiers should check exp, nbf and aud on every request.

Signing algorithms fall into two groups. HMAC algorithms such as HS256 use one shared secret to sign and verify, so every verifier can also create tokens. RSA, RSA-PSS, ECDSA and EdDSA use a private key to sign and a public key to verify, which lets many services check tokens without being able to issue them. ECDSA and EdDSA produce much shorter signatures than RSA.

The security of an HMAC token depends entirely on the secret. A token contains everything needed to test guesses offline, so a dictionary word or short phrase can be found quickly. Use at least as many random bytes as the hash output, 32 for HS256. For asymmetric algorithms, keep the private key in a key management system and publish the public key, often as a JWK Set.

This generator signs with the browser’s Web Crypto API, the same implementation browsers use for HTTPS, so the result is a standard token that any compliant library can verify. Keys you generate here are created on your device and shown only to you. They are intended for development and testing; production keys belong in your server’s secure configuration, not in a browser tab.

Other useful tools