Choosing a JWT signing algorithm

HS256, RS256, PS256 or ES256? The right choice depends on who verifies your tokens, what your ecosystem supports and how you manage keys.

Decision guide

  1. Does anyone other than the issuer verify the tokens? If no, HS256 with a random 256-bit secret is a good choice. If yes, use an asymmetric algorithm so verifiers can't mint tokens.
  2. Do you need the broadest compatibility? Choose RS256 — every JWT library and identity provider supports it.
  3. Do you want small tokens and fast signing? Choose ES256 (P-256). Signatures are 64 bytes versus 256 bytes for RS256 with a 2048-bit key.
  4. Do you want modern RSA padding? PS256 uses RSA-PSS with the same RSA keys; support is widespread but not universal.

Whatever you choose, configure verifiers to accept only that algorithm.

All supported algorithms

algDescriptionSigning key
HS256HMAC using SHA-256Secret ≥ 256 bits
HS384HMAC using SHA-384Secret ≥ 384 bits
HS512HMAC using SHA-512Secret ≥ 512 bits
RS256RSA signature (PKCS#1 v1.5) using SHA-256RSA private key ≥ 2048 bits
RS384RSA signature (PKCS#1 v1.5) using SHA-384RSA private key ≥ 2048 bits
RS512RSA signature (PKCS#1 v1.5) using SHA-512RSA private key ≥ 2048 bits
PS256RSA-PSS signature using SHA-256 and MGF1RSA private key ≥ 2048 bits
PS384RSA-PSS signature using SHA-384 and MGF1RSA private key ≥ 2048 bits
PS512RSA-PSS signature using SHA-512 and MGF1RSA private key ≥ 2048 bits
ES256ECDSA using P-256 and SHA-256EC private key, P-256
ES384ECDSA using P-384 and SHA-384EC private key, P-384
ES512ECDSA using P-521 and SHA-512EC private key, P-521

Key and signature sizes

HMAC signatures are 32, 48 or 64 bytes. RSA signatures equal the modulus size (256 bytes at 2048 bits, 512 bytes at 4096 bits). ECDSA signatures are 64, 96 or 132 bytes for ES256, ES384 and ES512. Signature size adds directly to the token length that travels with each request.

Create a secret or key pair for any of these algorithms, with PEM, JWK and JWKS export.

Generate keys