JWT Generator

Build and sign a JSON Web Token with HS256, HS384 or HS512. Everything runs in your browser using the native Web Crypto API — your secret and the token are never sent anywhere and nothing is stored.

The secret is used only to sign the token in your browser and never leaves your device.

How to use the JWT generator

  1. Edit the Header and Payload JSON — both must be valid JSON. Use Add exp (+1h) to insert an expiry claim.
  2. Choose an algorithm (HS256, HS384 or HS512) and enter your secret.
  3. The signed token is generated automatically. Click Copy to grab it.

A JWT is three base64url parts joined by dots: header.payload.signature. To read an existing token, use the companion JWT Decoder. Because HMAC is symmetric, the same secret both signs and verifies.

More PAYATE tools

Frequently asked questions

What is a JWT?

A JSON Web Token is a compact, URL-safe token made of three base64url parts separated by dots: a header, a payload of claims, and a signature. It is widely used to carry authentication and authorization data between a client and a server.

What does this tool do?

It builds a signed JWT from the header and payload JSON you provide, base64url-encodes each part, and signs header.payload with an HMAC algorithm (HS256, HS384 or HS512) using your secret. The result is a complete, verifiable token you can copy.

Is my secret sent anywhere?

No. Signing uses your browser's native Web Crypto API — the secret and the generated token stay entirely in your browser. Nothing is uploaded to a server and nothing is stored.

What is the difference between HS256, HS384 and HS512?

They are the same HMAC scheme with a different SHA-2 hash: HS256 uses SHA-256, HS384 uses SHA-384 and HS512 uses SHA-512. HS256 is the most common; the larger variants produce a longer signature. All three are symmetric — the same secret signs and verifies.

How do I add an expiry (exp) claim?

Add a numeric exp claim to the payload holding a Unix timestamp in seconds. Use the Add exp (+1h) helper to insert one an hour in the future automatically. Common time claims are iat (issued at), nbf (not before) and exp (expires).

Can I verify or read a token?

To read the contents of an existing token, use the companion JWT Decoder. This generator only creates and signs tokens. Because HMAC is symmetric, anyone can verify a token only if they hold the same secret.