Security

JWT Claims Builder

Build a JSON Web Token payload (claims) with standard registered claims like iss, sub, aud, exp and iat plus custom claims.

Last reviewed by the Radiatus Cloud team

Build a JSON Web Token payload with standard and custom claims.

Need this handled by experts?

Radiatus runs VAPT, managed SOC & security engineering for regulated teams.

Book a free security consult

Build a JWT payload

The payload of a JSON Web Token carries its claims, the pieces of information it asserts, such as who issued it, who it identifies, and when it expires. This builder assembles a well-formed payload from the standard registered claims defined by the JWT specification: issuer, subject, audience, issued-at, not-before and expiry, and lets you add any custom claims your application needs. It automatically sets the issued-at and not-before timestamps to now and computes the expiry from the minutes you specify.

Timestamps use Unix epoch seconds, as the standard requires, and custom values that look like numbers or booleans are typed accordingly.

Claims and token design

Including an expiry claim is important so tokens do not remain valid indefinitely, and the issuer and audience claims let a recipient verify that a token was meant for it and came from a trusted source. Keeping the payload small matters because the token is sent with every request, and remember that the payload is only base64-encoded, not encrypted, so it must never contain secrets or sensitive personal data.

This tool builds the payload only; signing it with a secret or key to produce a complete token is a separate step done securely on the server. All processing happens locally in your browser.

Related tools

  • Password Strength Checker — Measure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
  • Password Generator — Generate strong random passwords and passphrases in your browser using the Web Crypto API. Nothing is transmitted, logged or stored.
  • Hash Generator — Generate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.
  • Base64 Encoder/Decoder — Encode and decode Base64 in your browser, including URL-safe Base64 and UTF-8 text. Handles files and data URIs locally with nothing uploaded.

Frequently Asked Questions

What are registered claims?

They are standard claim names defined by the JWT specification, such as iss, sub, aud, exp, iat and nbf, with agreed meanings.

Why set an expiry claim?

The exp claim limits how long a token is valid, so a stolen or stale token cannot be used indefinitely. The tool computes it from the minutes you enter.

Is the payload encrypted?

No. A standard JWT payload is only base64-encoded and readable by anyone, so never put secrets or sensitive personal data in it.

Does this sign the token?

No. It builds the payload. Signing it with a secret or private key to create the full token should be done securely on the server.

Privacy & Security

Everything runs in your browser; nothing is uploaded.

Data: None
Client-side-Side
Active
v1.0

How to Use

Fill in the standard claims and add custom ones, then copy the JSON payload.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.