Skip to content

JWT Generator

Build and sign a JSON Web Token with HS256, HS384 or HS512 from an editable header and claims, with an exp shortcut and an expiry readout.

JWT Generator

Quick-add claims
Only HMAC (shared-secret) signing runs client-side. RS/ES/PS algorithms need a private key and a server or KMS to stay secret.
Signed tokenHS256

Fix the JSON above to generate a token.

Signing happens entirely in your browser via the Web Crypto API. Your secret and claims never leave this page.

Updated . Provided as is. Check the output before you rely on it in production.

How to use JWT Generator

  1. 1

    Edit the header

    Keep the default header with alg and typ, or adjust it. The alg field stays in sync with the algorithm selector.

  2. 2

    Write your claims

    Enter the payload as JSON, or use the quick-add buttons for iat, exp, sub, iss, and aud.

  3. 3

    Choose algorithm and secret

    Pick HS256, HS384, or HS512 and enter the shared secret used to sign and later verify the token.

  4. 4

    Read the preview

    Check the decoded claims and expiry status to confirm the token contains what you expect.

  5. 5

    Copy the token

    Copy the signed header.payload.signature string into your app, tests, or API client.

Questions and answers

What does this JWT generator do?
A JSON Web Token (JWT) is a base64url-encoded header and payload of claims plus a signature, used to pass identity between services. This generator builds one from JSON header and claims editors, signs it with your secret using HS256, HS384 or HS512 via Web Crypto, and shows when its exp claim expires.
Which signing algorithms are supported?
HS256, HS384, and HS512, which use a shared secret (HMAC). Asymmetric algorithms like RS256 or ES256 require a private key and a server, so they are intentionally out of scope for a client-side tool.
Is the token signed in my browser?
Yes. The header, payload, and secret are base64url-encoded and signed locally with the Web Crypto API. Nothing is uploaded to a server.
How do I set an expiry time?
Use the exp quick-add button with a minutes value, or add an exp claim manually as a Unix timestamp. The preview then shows the resulting expiry and whether it is still valid.
Can I edit the header and claims freely?
Yes. Both are JSON editors with live validation. The algorithm selector keeps the header's alg field in sync so the token stays consistent.
For AI agents: how to call this tool

Machine-readable contract, endpoints and examples. Humans can ignore this section.

Best Path For Builders

Browser workflow

Runs instantly in the browser with private local processing and copy/export-ready output.

Browser Workflow

This tool is optimized for instant in-browser execution with local data handling. Run it here and copy/export the output directly.

/jwt-generator/

For automation planning, fetch the canonical contract at /api/tool/jwt-generator.json.