JWT Generator Online
Create and sign JSON Web Tokens for development, API testing, and debugging. Choose HS256, HS384, or HS512, edit the header and claims, then sign locally — the secret never leaves this browser.
Create and sign a JWT
Signing uses the Web Crypto API in this tab. Secrets are not uploaded, stored, or added to the URL.
Advertisement
What Is a JWT Generator?
A JWT generator builds a signed JSON Web Token from a header, a payload of claims, and a secret. Developers use it to create test tokens for APIs, auth middleware, and local apps. This page signs HS256, HS384, and HS512 in the browser with the Web Crypto API, so the secret is not uploaded. Treat the result as a development fixture — production signing keys belong on a server, not in a web form.
How to Generate a JWT Token
- Choose the signing algorithm: HS256, HS384, or HS512. The header
algstays in sync. - Edit the JWT header JSON if you need extra header fields besides
algandtyp. - Add or edit payload claims. Use the chips for
iss,sub,aud,iat,nbf, andexpwithout wiping custom keys. - Enter a development secret, or generate a random one. Do not paste a production signing key.
- Generate the token (or press Ctrl+Enter / Cmd+Enter).
- Copy the compact JWT and send it as a Bearer token in your test client.
Generated tokens are for development and testing unless your architecture intentionally keeps the same secret on a trusted server. This tool does not manage production keys.
JWT Header, Payload, and Signature
RFC 7519 defines a JSON Web Token as claims in a compact, URL-safe format. The usual JWS compact serialization is three Base64URL segments:
base64url(header) + "." + base64url(payload) + "." + base64url(signature)The header names the algorithm (alg) and type (typ, usually JWT). The payload holds claims: registered ones such as iss, sub, aud, iat, nbf, and exp, plus your own keys. The signature is HMAC over the first two segments:
signature = HMAC-SHA-256|384|512(
base64url(header) + "." + base64url(payload),
secret
)Encoding is UTF-8, then Base64URL (no padding, - and _ instead of + and /). Standard Base64 will break verification. JWT compact form is signed, not encrypted: anyone who has the token can read the payload. Signature verification is a separate step from reading those claims.
Supported JWT Algorithms
This JWT signing tool implements HMAC algorithms only. HS256 is the usual choice for local API tests. HS384 and HS512 use longer SHA hashes and produce larger signatures. RSA and ECDSA (RS256, ES256) need a private key and are not offered here so the page stays a generator, not a key-management product.
HS256
HMAC with SHA-256. Widely supported in libraries and gateways. An HS256 JWT generator is what most people want for Postman, curl, and middleware fixtures.
HS384
HMAC with SHA-384. Use it when a service under test already requires HS384. The signing input is the same compact string; only the hash changes.
HS512
HMAC with SHA-512. Same workflow as HS256 with a longer digest. Pick it to match a backend that already configured HS512 — not because a browser generator is “more secure” than your server.
JWT Claims You Can Add
iss— issuer. Who created the token.sub— subject. Usually a user or service id.aud— audience. The API or app that should accept it.iat— issued-at, Unix seconds. This generator does not overwrite an iat you already set.nbf— not-before. Reject the token until this time.exp— expiration. Presets: 15 minutes, 1 hour, 24 hours, 7 days, or a custom minute count.
You can keep custom claims such as role or scope. Quick-add only merges the selected key. Claim values are JSON, not magic strings: exp must be a number (Unix time), not a date label.
JWT Generator Examples
These payloads are samples for local work. They are not real authentication credentials. Sign them with a throwaway secret that exists only on this page and in your test process.
API testing
Send a Bearer token from Postman or curl while you build an authorization middleware. The claims below are fixtures, not credentials.
{
"sub": "qa-user",
"iss": "local-tests",
"aud": "orders-api",
"iat": 1700000000,
"exp": 1700003600,
"scope": "orders:read"
}Authentication / session development
Prototype a short-lived session token while a login route is unfinished. Keep the signing secret on this page only.
{
"sub": "user-42",
"name": "Ada Lovelace",
"role": "member",
"iat": 1700000000,
"exp": 1700000900
}Testing expiry with exp
Use a past exp to confirm a 401 path, or a 15-minute exp to watch a client refresh flow.
{
"sub": "exp-check",
"iat": 1700000000,
"exp": 1700000001
}Issuer and audience checks
Confirm an API rejects tokens whose iss or aud does not match the expected values.
{
"sub": "svc-worker",
"iss": "auth.example.test",
"aud": "billing-api",
"iat": 1700000000,
"exp": 1700086400
}Local development sample
A dummy token for a local Next.js or Express app. Never treat generated examples as production credentials.
{
"sub": "dev-user",
"env": "local",
"iat": 1700000000,
"exp": 1700086400
}Common JWT Generator Mistakes
- Invalid JSON. A trailing comma or a single-quoted key will fail. Use the validator messages, or run the object through the JSON validator or JSON formatter.
- Wrong algorithm. If the header says HS256 and the server expects HS512, verification fails even with the same secret.
- Missing a segment. A JWT has three dot-separated parts. Two parts is not a signed JWS.
- Encoding is not encryption. Base64URL is reversible. Do not put passwords or card numbers in a JWT payload.
- Production secrets in a browser. Anyone with DevTools can read the field. Use a test secret.
- Bad exp timestamps.
expis Unix seconds, not milliseconds. A millisecond value looks “valid for decades” or already expired, depending on the library. - Wrong Base64. Standard Base64 with
+,/, and=is not Base64URL. See Base64 encode and decode for the related encoding, then remember JWTs drop padding. - Trusting a decoded payload. Reading claims is not the same as verifying the HMAC. A decoded JWT is not automatically trusted.
- Confusing generate with verify. This page creates tokens. Checking a token you already have is a decoder/verifier job.
JWT Generator for API Testing
People look for a JWT generator online, a JWT token generator, or a free JWT encoder when they need a Bearer token before login exists. An online JWT generator is useful for that: set sub, choose HS256, sign with a shared test secret, and call the API. A JWT signing tool on the web is not a substitute for your identity provider. Create a JWT token here, store the same secret in the test server config, and rotate it when the environment is torn down.
When the token must travel in a query string, percent-encode the URL or inspect it with the query string parser. HMAC itself is related to a hash generator, but a JWT is a structured token, not a raw digest. Opaque credentials belong in an API key generator.
JWT Generator vs JWT Decoder
Generate when you need a new signed token. Decode when you already have a token and want to read header and claims. Verification means recomputing the HMAC with a secret and comparing signatures — that is not the same as decoding. This page stays a generator. For inspection and optional HMAC checks, decode a JWT token on the dedicated decoder.
Frequently Asked Questions
- What is a JWT generator?
- It builds a signed JSON Web Token from header JSON, payload claims, and a secret. This one signs HS256, HS384, and HS512 in your browser for development and API tests.
- What is a JWT token used for?
- APIs and apps use JWTs as compact access or session tokens. The server verifies the signature and reads claims such as sub, exp, and roles. A generated token is a Bearer string, not an encrypted vault.
- How do I generate a JWT token?
- Choose HS256, HS384, or HS512, edit header and payload, enter a development secret, then generate. Copy the three-part token into Authorization: Bearer.
- Is this JWT generator free?
- Yes. There is no signup and no paid tier on this page. Signing runs in the browser.
- Is this JWT generator secure?
- Signing uses the Web Crypto API and the secret is not sent to EverydayTools. It is still a browser form: anyone with the tab can see the key. Do not paste production secrets.
- Does my JWT secret leave the browser?
- No. HMAC runs locally. The secret is not uploaded, logged, stored, or placed in the URL. Close the tab when you finish.
- Which JWT algorithms are supported?
- HS256 (HMAC-SHA-256), HS384 (HMAC-SHA-384), and HS512 (HMAC-SHA-512). RS256 and ES256 are not offered because they need a private key pair.
- Can I generate an HS256 JWT?
- Yes. HS256 is the default. The header alg updates when you pick the chip, then the signature uses SHA-256.
- What claims can I add to a JWT?
- Registered claims iss, sub, aud, iat, nbf, and exp, plus any custom JSON keys. Quick-add merges into your object so other fields stay.
- Can I use this JWT generator for API testing?
- Yes. That is the main use: fixtures for Postman, curl, and local middleware. Put the same test secret in the server under test.
- What is the difference between a JWT generator and JWT decoder?
- A generator creates a new signed token. A decoder reads an existing token’s header and payload. Verification checks the HMAC. Use the JWT decoder page to inspect tokens you already have.
- Are JWT payloads encrypted?
- No. Compact JWTs here are JWS: signed, not encrypted. Anyone can Base64URL-decode the payload. Do not put secrets in claims.
- Can I use a generated JWT in production?
- Not as a substitute for server-side signing. Production issuers keep the key off the browser. Use this output only in environments that already share a test secret.
Last editorial review: 2026-10-03.
Advertisement