Create and sign JSON Web Tokens instantly.

Build JWT headers and claims, set expiration times, choose a signing algorithm and generate your token directly in your browser.

πŸ”’ Secrets and private keys stay in your browser.Have a JWT? β†’ Decode it at JWTDecoder.com

Templates are examples, not universal security recommendations.

Create JWT

Loading…

JWT payloads are encoded, not encrypted.Do not put passwords, private keys or other secrets inside the payload unless the token is separately encrypted using an appropriate mechanism.

Signing

HS256 β€” HMAC using SHA-256.The same secret is used to sign and verify the JWT. Keep the secret private.

Symmetric: anyone who can verify an HS256 token can also create one. RFC 7518 Β§3.2 requires a key of at least 256 bits (32 bytes).

Secret encoding
Generate secure secret

Generated locally in your browser with crypto.getRandomValues. Never stored.

The token updates live; Generate refreshes iat/exp to the current time.

Import JWT β†’ modify β†’ re-sign

The header and claims are loaded into the builder. The original signature is discarded β€” you sign the new token with your own key.

Modifying a signed JWT invalidates the existing signature. A valid new signature requires legitimate signing credentials.

Signing a JWT does not encrypt its payload

JWTEncoder is a development, testing and debugging utility. The token it produces is header.payload.signature: the first two parts are Base64URL-encoded JSON that anyone can read, and the signature proves the token was created by someone holding your key.

Every token is self-verified before you copy it, so a key mismatch or implementation problem shows up here instead of in your API logs. The algorithm you select always governs signing β€” it is never switched automatically based on the key you paste.

Beyond the builder: a key generator for RSA, EC and HMAC keys with PEM, JWK and JWKS export; a test token generator that produces expired, not-yet-valid, wrong-audience and tampered tokens for your test suite; and code in seven languages that reproduces the token you built.

To debug an existing token β€” timeline, claim validation, security checks β€” use JWTDecoder.com. Tokens move between the two tools only through your clipboard.

Keyboard shortcuts

Ctrl/⌘ + Enter generate JWT (refreshes iat/exp) · Ctrl/⌘ + Shift + Enter copy JWT

Frequently asked questions

Are my secrets and private keys safe?

Tokens are built and signed entirely in your browser with the Web Crypto API. Secrets, private keys, payloads and generated tokens are never uploaded, logged, stored or put in URLs. Still, prefer test keys: never paste production signing keys into any website.

Is the payload encrypted?

No. Signing a JWT does not encrypt its payload. Anyone who has the token can decode the header and claims. The signature only proves who created the token and that it hasn't been changed.

Which algorithms are supported?

HS256, HS384 and HS512 with a shared secret; RS256, RS384, RS512, PS256, PS384 and PS512 with an RSA private key; and ES256, ES384 and ES512 with an EC private key on P-256, P-384 or P-521. Keys can be PEM (PKCS#8, PKCS#1, SEC1) or JWK.

How do I set the expiration time?

Pick a duration such as 15 minutes or 1 day, enter a custom duration, choose an exact date and time, or type a Unix timestamp. The exact NumericDate value is always shown, in local time and UTC.

Why does my token fail verification elsewhere?

Check that the verifier uses the same secret bytes (encoding matters), the public key matching your private key, the same algorithm, and that exp/nbf/aud/iss match its expectations. JWTEncoder self-verifies every token before you copy it.