JWT Generator

Create signed JWT tokens for testing authentication flows.

⚠️ For testing only. Never use this to sign real tokens — secret keys should never leave your server.

What is a JWT?

A JSON Web Token (JWT) is a compact, URL-safe token with three parts: header.payload.signature, each Base64URL-encoded. The signature proves the token wasn't tampered with.

Security warning

Never use this tool to sign real production tokens. Real JWTs should be signed on a server with a secret key that never leaves the server environment. Use this tool only for local testing and learning.

Privacy

Everything runs in your browser. Your secret and payload are never uploaded.

Frequently Asked Questions

What is a JWT generator?

A tool that creates a signed JSON Web Token from a header, payload, and secret key. Used for testing authentication flows.

Is this safe to use?

Only for testing. Never sign real tokens in a browser tool — secrets should never leave your server.

Which algorithms are supported?

HS256, HS384, and HS512 (HMAC-SHA). RS256 (RSA) is not supported because it requires a private key.

What claims are added automatically?

iat (issued at) is always added. exp (expiration) is added if you set 'Expires in' > 0.

Is my secret uploaded?

No. Everything runs in your browser.

Related Tools