JWT Encoder

Build a token for local testing: edit the payload, set an expiry and sign it with a shared secret. Signing uses Web Crypto in your browser.

How it works

The header and payload are serialised to JSON, Base64URL-encoded and joined with a dot. An HMAC of that string with your secret is the signature.

RFC 7518 requires an HMAC key at least as long as the hash output: 32 bytes for HS256. Shorter secrets get a warning.

Everything above runs in JavaScript inside this tab. Your data is not uploaded. Inputs are remembered in this browser only so they survive a reload; you can switch that off on the privacy page.

Questions

Should I create production tokens here?

No. Production tokens should be minted by your auth server. This is for tests, fixtures and debugging.

Why only HMAC algorithms?

Signing with RS or ES algorithms needs a private key, which should not be pasted into web pages. Verify RS/ES tokens in the JWT Decoder with the public key instead.