Create and sign JSON Web Tokens instantly.
Build JWT headers and claims, set expiration times, choose a signing algorithm and generate your token directly in your browser.
Templates are examples, not universal security recommendations.
Create JWT
Loadingβ¦
Signing
Symmetric: anyone who can verify an HS256 token can also create one. RFC 7518 Β§3.2 requires a key of at least 256 bits (32 bytes).
Signing a JWT does not encrypt its payload
JWTEncoder is a development, testing and debugging utility. The token it produces is header.payload.signature: the first two parts are Base64URL-encoded JSON that anyone can read, and the signature proves the token was created by someone holding your key.
Every token is self-verified before you copy it, so a key mismatch or implementation problem shows up here instead of in your API logs. The algorithm you select always governs signing β it is never switched automatically based on the key you paste.
Beyond the builder: a key generator for RSA, EC and HMAC keys with PEM, JWK and JWKS export; a test token generator that produces expired, not-yet-valid, wrong-audience and tampered tokens for your test suite; and code in seven languages that reproduces the token you built.
To debug an existing token β timeline, claim validation, security checks β use JWTDecoder.com. Tokens move between the two tools only through your clipboard.
Keyboard shortcuts
Ctrl/β + Enter generate JWT (refreshes iat/exp) Β· Ctrl/β + Shift + Enter copy JWT
Frequently asked questions
Are my secrets and private keys safe?
Tokens are built and signed entirely in your browser with the Web Crypto API. Secrets, private keys, payloads and generated tokens are never uploaded, logged, stored or put in URLs. Still, prefer test keys: never paste production signing keys into any website.
Is the payload encrypted?
No. Signing a JWT does not encrypt its payload. Anyone who has the token can decode the header and claims. The signature only proves who created the token and that it hasn't been changed.
Which algorithms are supported?
HS256, HS384 and HS512 with a shared secret; RS256, RS384, RS512, PS256, PS384 and PS512 with an RSA private key; and ES256, ES384 and ES512 with an EC private key on P-256, P-384 or P-521. Keys can be PEM (PKCS#8, PKCS#1, SEC1) or JWK.
How do I set the expiration time?
Pick a duration such as 15 minutes or 1 day, enter a custom duration, choose an exact date and time, or type a Unix timestamp. The exact NumericDate value is always shown, in local time and UTC.
Why does my token fail verification elsewhere?
Check that the verifier uses the same secret bytes (encoding matters), the public key matching your private key, the same algorithm, and that exp/nbf/aud/iss match its expectations. JWTEncoder self-verifies every token before you copy it.