JWT Generator
Generate a signed JSON Web Token from a payload and secret, instantly in your browser.
How to use the JWT Generator
- Enter the payload as JSON, for example {"sub":"123","name":"Ada","exp":1893456000}.
- Choose the signing algorithm: HS256, HS384 or HS512.
- Enter the shared secret your application uses to verify tokens.
- Click Run to generate the signed token, ready to paste into an Authorization: Bearer header.
How the JWT Generator works
The generator builds a header such as {"alg":"HS256","typ":"JWT"}, Base64URL-encodes it and your payload, and joins them with a dot. It then computes an HMAC of that string with your secret, using SHA-256, SHA-384 or SHA-512, and appends the Base64URL-encoded signature as the third part.
Signing happens entirely in your browser with the Web Crypto API. Use it for development and testing; in production, issue tokens from your server and keep secrets out of client-side tools. Paste the result into the JWT Decoder to inspect it.
Frequently asked questions
- Is this tool free?
- Yes. Generate JWTs at no cost, with no account required.
- Which signing algorithms are supported?
- HS256, HS384, and HS512, all HMAC-based algorithms signed with your secret using your browser's built-in cryptography.
- Does my secret leave my browser?
- No. Signing happens entirely client-side; your payload and secret are never sent to a server.