tooldura
All tools

JWT Generator

Build a token with your own claims and sign it with HMAC, RSA or ECDSA

Your own claims go here. Issued-at and expiry are filled in for you, so leave iat and exp out of this box unless you want to pin them to an exact second.

One secret, shared by whoever signs and whoever checks. Simplest, and the right choice when both ends are yours.

Secret encoding

19 bytes of key material. Everything is signed in your browser, so this secret never travels anywhere.

Heads up: HS256 wants at least 32 bytes of key, and this one is 19. A short secret can be brute-forced offline from any token you hand out, which recovers the key and lets anyone mint their own.
Signed token
Fix the payload and the signed token appears here.

About JWT Generator

The JWT Generator builds a signed token from claims you write yourself, for the moment you need a valid token to test an endpoint, a middleware or a login flow and do not want to run the whole issuer to get one. You write the claims, pick a lifetime, and iat and exp are filled in from the current second. Pick "Already expired" instead and you get the opposite: a token that ran out five minutes ago, issued an hour before that, for checking your service turns it away. Signing runs on crypto.subtle and covers all twelve algorithms in the JWA registry. HMAC uses the secret you type, and the tool measures it against what RFC 7518 requires, because a two-word secret is the difference between a signature and a formality. The RSA and ECDSA families never ask for a private key: the tool generates a throwaway pair in your browser, signs with the private half, and gives you only the public half to verify against.

✦FreeNo paywalls or tiers
⬡No SignupNothing to create
⚡InstantNo setup, no install
⊞Any DeviceMobile, tablet, desktop

The guide behind this tool

Signing a JWT: Which Algorithm, and How Long the Key Has to Be

HS256 hands every verifier the power to forge. RS256 does not. And the 32-byte minimum in RFC 7518 is the line between a signature and a formality.

8 min read

How to use JWT Generator

  1. 1

    Write your claims as a JSON object. Anything is allowed: sub, a role, a tenant id, whatever the API you are testing reads.

  2. 2

    Pick the family and the hash size: HMAC for a shared secret, or RSA, RSA-PSS and ECDSA for a key pair.

  3. 3

    On HMAC, type the secret your API verifies with, or generate a strong random one if you are creating both sides. On a key pair, the tool makes the key itself and shows you the public half as PEM or JWK.

  4. 4

    Copy the token and send it as an Authorization header.

Frequently Asked Questions

It makes its own. Picking RSA, RSA-PSS or ECDSA generates a throwaway key pair in your browser through crypto.subtle, signs with the private half, and shows you only the public half as PEM or JWK. That private key is created non-extractable, so nothing running on the page can read it back out, and it is gone the moment you reload. You are never asked to paste a production private key, which is a habit worth keeping whatever any given page claims to do. To check the result, copy the public key into the JWT decoder.