What it does
A JSON Web Token (JWT, RFC 7519) is a compact, URL-safe string with three parts separated by dots: a header that names the signing algorithm, a payload of claims, and a signature over the first two. APIs use JWTs as bearer tokens, and identity providers use them as ID tokens.
This tool builds and signs a token from a JSON payload. It supports:
- HS256, HS384, HS512: HMAC with a shared secret, as text or Base64.
- RS256, RS384, RS512 and PS256, PS384, PS512: RSA signatures with a PEM private key.
- ES256, ES384, ES512: ECDSA signatures with an EC private key.
How to use
- Write the payload as a JSON object, or click Sample.
- Choose the Algorithm and enter the secret or paste the PEM private key at the top of the input box.
- Optionally set iat to the current time, add an expiry (exp), or add extra header fields such as a key ID.
- Copy the token from the output. Paste it into the JWT decoder to inspect it.
Example
With the secret your-256-bit-secret, the payload below signed with HS256 gives the well-known example token from jwt.io:
{"sub":"1234567890","name":"John Doe","iat":1516239022}
The header is always written as {"alg":"HS256","typ":"JWT"} followed by any extra fields you add; alg always follows the selected algorithm.
Good practice
Keep tokens short-lived with an exp claim, and set iss and aud so a token for one service cannot be replayed against another. On the server, always verify the signature with an explicit list of allowed algorithms, and reject none. HMAC secrets should be long and random, at least as long as the hash output (32 bytes for HS256).
FAQ
› Which algorithm should I pick?
Use the one your server verifies. HS256 uses a shared secret and is common inside one system. RS256 and ES256 sign with a private key and let anyone verify with the public key, which suits tokens checked by several services. ES256 gives much shorter signatures than RS256.
› What private key formats are accepted?
PEM keys in PKCS#8 (BEGIN PRIVATE KEY), PKCS#1 RSA (BEGIN RSA PRIVATE KEY) and SEC1 EC (BEGIN EC PRIVATE KEY). Encrypted keys must be exported without a passphrase first. For ES256, ES384 and ES512 the key must be on the P-256, P-384 or P-521 curve respectively.
› Is the payload of a JWT secret?
No. The header and payload are only Base64URL-encoded, and anyone holding the token can read them. The signature prevents changes, not reading. Never put passwords or other secrets in a JWT payload.
› Is my secret or private key stored or sent anywhere?
No. Signing runs in your browser with the Web Crypto API. The secret or key is kept only in memory on this page; it is not saved, not written to the address bar and not included in share links. Still, avoid pasting production keys into any web page you do not control.