JWT Generator - Create and Verify HS256, HS384 & HS512 JSON Web Tokens
JWT Generator & Verifier
Sign tokens with a shared secret and check signatures
Sign and Verify
Create a token for testing an API, or check whether a token was signed with a given secret.
Time Claims
Add iat and exp in one click and see expiry and not-before checks when verifying.
Key Strength Check
Warns when the secret is shorter than the hash output, as RFC 7518 requires.
Private
Everything runs in your browser; nothing you paste is uploaded.
How HMAC-Signed JWTs Work
A JWT is three base64url parts joined by dots: a header naming the algorithm, a payload of claims such as sub, iat and exp, and a signature. With HS256 the signature is an HMAC-SHA-256 of the first two parts using a secret shared by whoever creates and whoever checks the token. Anyone can read the payload, so never put passwords or secrets in it; the signature only proves it was not changed.
Use a long random secret, at least 32 bytes for HS256, and keep it on the server. Tokens signed with RSA or ECDSA keys (RS256, ES256) need a public/private key pair and cannot be checked with a shared secret; you can still decode them with the JWT decoder. For production, always issue tokens from server-side code with a maintained library.
Key Takeaways
- Readable by anyone: JWT payloads are encoded, not encrypted.
- Long secrets: Use at least as many random bytes as the hash size.
- Check exp: A valid signature on an expired token should still be rejected.