JWT Generator
A JWT generator builds a JSON Web Token: a base64url-encoded header and payload joined to an HMAC-SHA256 signature over both, computed with your secret. This one signs in the browser with the Web Crypto API and updates as you type, so you can produce test tokens without pasting a secret into a third-party server.
Last reviewed by the Radiatus Cloud team
Need this built for your product?
We design, build & host secure software & APIs.
What the tool produces
The header is fixed at {"alg":"HS256","typ":"JWT"}. The payload is whatever JSON you enter. Both are serialised, base64url-encoded, joined with a dot, and that string is signed with HMAC-SHA256 using the secret's UTF-8 bytes. The signature is base64url-encoded and appended after a second dot. Base64url differs from ordinary base64 by using hyphen and underscore instead of plus and slash, and by dropping the trailing equals padding, which is why a JWT is safe in a URL or header without further escaping.
Claims worth putting in the payload
| Claim | Meaning | Example |
|---|---|---|
| sub | Subject, the user or client ID | "sub":"user_42" |
| iss | Issuer | "iss":"https://auth.example.com" |
| aud | Intended audience | "aud":"api.example.com" |
| iat | Issued at, Unix seconds | "iat":1756900000 |
| exp | Expiry, Unix seconds | "exp":1756903600 |
| nbf | Not valid before | "nbf":1756900000 |
Timestamps are seconds, not milliseconds. A token with exp in milliseconds is valid for roughly 55,000 years, which is a real bug people ship.
Secret length
RFC 7518 requires an HS256 key of at least 256 bits, 32 bytes. Short secrets such as secret or password123 are cracked offline in seconds from a single captured token, because the attacker can verify guesses without contacting the server. Generate 32 or more random bytes and treat the secret like a password database.
HS256 versus RS256
HS256 uses one shared secret for signing and verifying, so every service that verifies tokens can also forge them. RS256 and ES256 sign with a private key and verify with a public one, which suits systems where many services verify tokens issued by one authority. This tool covers HS256 only. Whatever algorithm you use, the verifier must pin it: accepting whatever the header claims is the route to the alg: none attack and to HS256 tokens signed with the RSA public key.
Related tools
- JWT Decoder — Decode JWT header and payload, inspect claims and expiry, and spot common security flaws. Runs locally, your tokens are never transmitted.
- JWT Risk Analyzer — Paste a JWT to decode its header and payload and flag security risks: alg none, jku/x5u header injection, missing expiry, millisecond timestamps and personal data in claims.
- HMAC Generator — Generate HMAC signatures with SHA-256 and other algorithms, and use them correctly.
- Hash Generator — Generate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.
Frequently Asked Questions
Is my secret sent to a server?
No. Signing happens with crypto.subtle in your browser, and the page makes no network request with the payload or secret.
Why does the token change every time I edit the payload?
Because the signature covers the exact bytes of the header and payload. Any change, including whitespace or key order, produces a different signature. That is the property a verifier relies on.
Can I decode a JWT to see its contents without the secret?
Yes. The header and payload are only base64url-encoded, not encrypted. Anyone holding a token can read it. The secret is needed only to verify or forge the signature.
What expiry should I use?
Minutes for access tokens, days to weeks for refresh tokens, and never omit exp entirely. A token that cannot expire can only be revoked by rotating the secret for everyone.
Does the tool support RS256 or custom headers?
Not in this version. The header is fixed to HS256. Use the RSA key generator to produce a key pair and sign RS256 tokens in your own code.
Privacy & Security
All processing happens locally in your browser — nothing is uploaded.
How to Use
Edit the payload and secret, then click Generate to get a signed HS256 JWT.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
JWT Decoder
SecurityDecode JWT header and payload, inspect claims and expiry, and spot common security flaws. Runs locally, your tokens are never transmitted.
JWT Risk Analyzer
SecurityPaste a JWT to decode its header and payload and flag security risks: alg none, jku/x5u header injection, missing expiry, millisecond timestamps and personal data in claims.
HMAC Generator
SecurityGenerate HMAC signatures with SHA-256 and other algorithms, and use them correctly.