JWT Secret Generator
Generate a strong random secret for signing JSON Web Tokens with HMAC (HS256/384/512), in base64, hex or raw formats.
Last reviewed by the Radiatus Cloud team
Generate a strong random secret for signing JSON Web Tokens.
Need this handled by experts?
Radiatus runs VAPT, managed SOC & security engineering for regulated teams.
Generate a JWT signing secret
JSON Web Tokens signed with an HMAC algorithm such as HS256 rely on a shared secret key, and the security of every token depends entirely on that secret being long and random. This generator produces a strong random secret of a size appropriate to your algorithm, formatted as base64, hexadecimal or URL-safe base64. A thirty-two-byte secret suits HS256, forty-eight bytes HS384, and sixty-four bytes HS512, matching the output size of each hash.
Using a secret at least as long as the hash output ensures the full security of the algorithm is realised.
Protecting your tokens
If an attacker learns or guesses your JWT secret, they can forge valid tokens and impersonate any user, so a weak or hard-coded secret is a critical vulnerability. A random secret of sufficient length cannot be guessed, and keeping it out of source control and configuration files visible to others is essential. Rotate the secret periodically and immediately if you suspect it has leaked.
The secret is generated locally using the browser secure random generator where available, so it is never transmitted. Store it securely in an environment variable or secrets manager. All generation happens locally in your browser.
Related tools
- Password Strength Checker — Measure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
- Password Generator — Generate strong random passwords and passphrases in your browser using the Web Crypto API. Nothing is transmitted, logged or stored.
- Hash Generator — Generate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.
- Base64 Encoder/Decoder — Encode and decode Base64 in your browser, including URL-safe Base64 and UTF-8 text. Handles files and data URIs locally with nothing uploaded.
Frequently Asked Questions
How long should a JWT secret be?
At least as long as the hash output: thirty-two bytes for HS256, forty-eight for HS384 and sixty-four for HS512, all generated randomly.
Why does the secret need to be random?
If it can be guessed, an attacker can forge valid tokens and impersonate users, so unpredictability is essential to token security.
What format should I use?
Base64 or URL-safe base64 are compact and common in configuration, while hex is sometimes preferred. All represent the same random bytes.
How should I store the secret?
Keep it out of source control in an environment variable or secrets manager, and rotate it periodically or immediately if it may have leaked.
Privacy & Security
Everything runs in your browser; nothing is uploaded.
How to Use
Choose the size and format, then generate a signing secret.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
Password Strength Checker
SecurityMeasure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
Password Generator
SecurityGenerate strong random passwords and passphrases in your browser using the Web Crypto API. Nothing is transmitted, logged or stored.
Hash Generator
SecurityGenerate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.