JWT Generator - Create and Verify HS256, HS384 & HS512 JSON Web Tokens

AdSense Placeholder
Slot: header_tool

JWT Generator & Verifier

Sign tokens with a shared secret and check signatures


                        

AdSense Placeholder
Slot: tool_mid_article

Sign and Verify

Create a token for testing an API, or check whether a token was signed with a given secret.

Time Claims

Add iat and exp in one click and see expiry and not-before checks when verifying.

Key Strength Check

Warns when the secret is shorter than the hash output, as RFC 7518 requires.

Private

Everything runs in your browser; nothing you paste is uploaded.

How HMAC-Signed JWTs Work

A JWT is three base64url parts joined by dots: a header naming the algorithm, a payload of claims such as sub, iat and exp, and a signature. With HS256 the signature is an HMAC-SHA-256 of the first two parts using a secret shared by whoever creates and whoever checks the token. Anyone can read the payload, so never put passwords or secrets in it; the signature only proves it was not changed.

Use a long random secret, at least 32 bytes for HS256, and keep it on the server. Tokens signed with RSA or ECDSA keys (RS256, ES256) need a public/private key pair and cannot be checked with a shared secret; you can still decode them with the JWT decoder. For production, always issue tokens from server-side code with a maintained library.

Key Takeaways

  • Readable by anyone: JWT payloads are encoded, not encrypted.
  • Long secrets: Use at least as many random bytes as the hash size.
  • Check exp: A valid signature on an expired token should still be rejected.
AdSense Placeholder
Slot: footer_leaderboard