JWT Generator
Build and sign JSON Web Tokens for testing and development. Edit the payload claims, add expiry with one click, choose any standard algorithm, and sign with a shared secret or a private key — or generate a test RSA/EC key pair. Signing uses the Web Crypto API; nothing is sent to a server.
Choose an algorithm, edit the JSON payload (use the quick buttons to set iat and exp), and enter a secret for HS256/384/512 or paste a PKCS#8 private key or JWK for RS, PS and ES algorithms. Click Sign to get a compact JWT, colour-coded into header, payload and signature.
Zero Server Uploads
Files process in local RAM
Instant WASM Speed
No waiting queues or lags
Unlimited Batching
Convert files without limits
Suggest a Feature or Improvement for JWT Generator
Need custom options, higher limits, or extra format support? Let our engineering team know!
How to use JWT Generator
- 1Choose the signing algorithm.
- 2Edit the payload claims and add iat/exp.
- 3Enter the secret or private key (or generate test keys).
- 4Sign and copy the token.
Choosing an algorithm
HS256 uses one shared secret for signing and verifying — simple, but every verifier can also create tokens. RS256, PS256 and ES256 sign with a private key and verify with a public key, so many services can verify without being able to issue tokens. ES256 gives short signatures and fast verification.
RFC 7518 requires HMAC secrets at least as long as the hash (32 bytes for HS256). Use the “Generate a strong secret” link rather than a word.
A JWT is signed, not encrypted
Anyone can decode the payload with the JWT Decoder, so never put passwords or sensitive personal data in it. Keep access tokens short-lived (exp of 5–60 minutes) and verify signatures with the JWT Signature Verifier.
Frequently Asked Questions
Can I use these tokens in production?
They're valid JWTs, but production tokens should be signed on your server with a secret that never touches a browser. Use this tool for testing, fixtures and debugging.
What key format do I need for RS256?
A PKCS#8 PEM private key (-----BEGIN PRIVATE KEY-----) or a private JWK. Convert older RSA PRIVATE KEY files with: openssl pkcs8 -topk8 -nocrypt -in key.pem
Is my data sent to your server?
No. This tool runs entirely in your browser using the Web Crypto API and JavaScript. Nothing you type or generate is uploaded, logged or stored.