Free to use, no account

JWT Encoder

Create a compact JSON Web Token from claims and sign it in this browser. Use this page for learning and test tokens, not production authentication.

Signing runs locally in this browser; nothing is uploaded or stored.

Use test data only. HMAC uses one shared secret for signing and verification. Never enter a production secret here.

This creates a token; it does not authenticate users, verify identities or replace a production identity provider.

Secret limit: 4 KiB. Claims limit: 192 KiB.

How do I create and sign a JWT?

Enter a JSON object of claims, choose HS256, HS384 or HS512, and provide a test secret. Optionally add an expiration time. The browser creates the token locally; copy it only into a safe test environment.

Frequently asked questions

How do I create and sign a JWT?

Enter a JSON object of claims, choose HS256, HS384 or HS512, and provide a test secret. Optionally add an expiration time. The browser creates the token locally; copy it only into a safe test environment.

Is my secret sent to a server?

No. Signing uses Web Crypto in this browser tab. The secret and claims are not uploaded or saved by this tool. Do not enter a production secret: browser extensions or a compromised device may still access page content.

Does creating a JWT log a user in?

No. A signed token by itself does not authenticate anyone. A server must validate its signature, issuer, audience, expiration and application-specific rules.

Can I use my production secret here?

No. Use only a disposable test secret. HMAC signing secrets are shared keys, and anyone who has the key can generate signatures. Keep production keys in a secure server-side secret manager.

Which algorithms are supported?

This tool supports HS256, HS384 and HS512 only. It does not support asymmetric algorithms such as RS256 or ES256.