JWT generator. Generate signed JWT tokens for testing with custom headers, standard claims, and HS256/HS384/HS512 signing.
100% browser-based — your data never leaves your device
Generate signed JWT tokens for testing with custom headers and payloads.
Type the JSON payload with standard claims (sub, exp, iat, iss) and any custom fields.
Enter a strong secret key used to sign the JWT with HS256, HS384, or HS512.
Customize header parameters like kid, typ, and cty in the advanced options.
Click Generate to create your signed JWT token and copy it to use in API requests.
Ctrl+Enter to generate jwt
Decode and inspect JWT tokens instantly.
Password GeneratorGenerate strong, secure random passwords with customizable options.
Passphrase GeneratorGenerate memorable, secure passphrases from word lists.
UUID GeneratorGenerate UUID v4 identifiers instantly.
UUID ValidatorValidate UUID strings and identify the version (v1, v2, v3, v4, v5).
Hash GeneratorGenerate SHA-1, SHA-256, SHA-384, and SHA-512 hashes from text.
JWT GeneratorGenerate signed JWT tokens for testing with custom headers and payloads.
Bcrypt Hash GeneratorGenerate bcrypt password hashes with configurable salt rounds.
API Key GeneratorGenerate cryptographically secure API keys in hex, base64, alphanumeric, and UUID formats.
HMAC GeneratorGenerate HMAC hashes with SHA-256, SHA-384, and SHA-512 algorithms.
AES EncryptEncrypt and decrypt text using AES-256-GCM with a password-based key.
This tool builds fully signed JWTs in your browser, letting you create realistic tokens for testing without standing up a separate signing service. Signing happens locally via the Web Crypto API, so your secret key never travels anywhere.
Authentication debugging is where this tool earns its time. When you need a token with a specific claim set to reproduce a bug, test an expiry edge case, or exercise authorization logic, minting one on demand beats waiting for a real login flow. API developers use it to create fixtures for integration tests, and security testers rely on it to check how their server reacts to tokens with unusual claims or header values.
The customization options matter for single sign-on work. Being able to set issuer, audience, and custom fields in the payload, then tune header parameters like kid, mirrors what real SSO providers emit, so you can validate your verification code against realistic tokens before you ever integrate. Because the tool signs with symmetric HS algorithms, you stay in full control of the secret.
A JWT generator is only as useful as it is safe to use with real secrets. If the secret key used to sign tokens is sent to a server, it can be logged, leaked, or reused, and anyone holding it can mint valid tokens for your entire system.
Here the entire signing process runs in your browser. The payload and the secret key stay on your device, nothing is uploaded, and the only artifact that leaves your screen is the finished token you copy out.
Type the JSON payload with standard claims (sub, exp, iat, iss) and any custom fields.
Enter a strong secret key used to sign the JWT with HS256, HS384, or HS512.
Customize header parameters like kid, typ, and cty in the advanced options.
Click Generate to create your signed JWT token and copy it to use in API requests.
Practical examples to help you get the most out of JWT Generator:
// Payload: {"sub":"user123","name":"John Doe","iat":1516239022,"exp":1516325422}
// Secret: my-secret-key
// Algorithm: HS256
// Result: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiJ1c2VyMTIzIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyLCJleHAiOjE1MTYzMjU0MjJ9.abc123...A weak secret key makes your JWT vulnerable to brute-force attacks. Use at least 256-bit (32-byte) cryptographically random secrets.
JWTs without an exp (expiration) claim never expire. Always include exp to limit the token's lifetime and reduce the risk of token theft.
HS256, HS384, and HS512 are supported. These are HMAC-based symmetric signing algorithms using SHA-256, SHA-384, and SHA-512 respectively.
No. All signing is done locally using the Web Crypto API. Your secret key and JWT payload never leave your browser.
Standard claims include sub (subject), exp (expiration), iat (issued at), iss (issuer), aud (audience), and custom claims can be added to the payload.
Yes. You can customize header parameters like kid (key ID), typ (type), and cty (content type) in the advanced options.
Build JWT payloads with standard claims (sub, exp, iat, iss) and custom fields.
HS256, HS384, HS512 signing algorithms with custom secret keys.
Customize header parameters like kid, typ, and cty.
All signing happens in your browser using the Web Crypto API.
JWT Generator is useful in a variety of scenarios across different workflows:
Generating JWT tokens for API authentication testing and development
Creating signed JWTs with custom claims for single sign-on (SSO) systems
Testing JWT token expiration and claim validation in security testing workflows
Use at least 256-bit (32-byte) secrets for HS256. Weak secrets can be brute-forced to forge tokens.
Always include an exp (expiration) claim. Short-lived tokens (15-60 minutes) reduce the risk of token theft.
Explore more tools in the Developer Workspace workspace:
JSON Formatter
Format, minify, validate, and explore JSON with tree view, JSONPath queries, and multi-format export — the complete JSON workbench.
JSON Validator
Validate JSON data and detect syntax errors with detailed error messages and line numbers.
JSON Compare
Compare two JSON files side by side with real-time diff highlighting.
JSON Path Tester
Test JSONPath expressions against JSON data and see matched results.
JSON Query Tool
Extract values from JSON using dot-notation and bracket-notation paths.
JSON Schema Generator
Generate JSON Schema (draft-07) from sample JSON data automatically.