Skip to content
JustTools

JWT Encoder

Build a JSON Web Token for testing: edit the header and claims, add issued-at and expiry times in one click, sign with a secret or private key — or generate a fresh key pair and JWKS.

Runs in your browser Free · no sign-up

At a glance

  • Signs JWTs with HS256/384/512, RS256/384/512, PS256/384/512, ES256/384/512 and EdDSA (Ed25519) using your browser’s Web Crypto API.
  • Edits the header and payload as JSON, pointing to the line and column of any mistake; alg is kept in step with the algorithm you pick.
  • Adds iat, exp (15 minutes to 30 days), nbf and a random jti in one click.
  • Generates a secure random secret of the right length, or an RSA, EC or Ed25519 key pair with the public key as PEM, JWK and JWKS (kid = RFC 7638 thumbprint).
  • Signs with keys in PEM (PKCS#8, PKCS#1 or SEC1) or JWK form, and warns when an HMAC secret is too short or a well-known example.
  • One click opens the new token in the JWT Debugger to verify it. Everything runs locally; keys never leave your device.

Step by step

How to create a JWT

  1. 1

    Pick the algorithm

    Choose HS256 for a shared secret, or RS256, ES256 or EdDSA for a key pair.

  2. 2

    Write the claims

    Edit the payload JSON and use the buttons to add iat and an exp such as 1 hour.

  3. 3

    Add a key

    Paste your secret or private key, or click Generate for a new one.

  4. 4

    Copy the token

    The signed token updates as you type. Copy it, or open it in the debugger to verify.

Features

Everything you need, nothing you don’t

Every JWS algorithm

HMAC, RSA, RSA-PSS, ECDSA and EdDSA — tokens your backend libraries accept.

Claim shortcuts

Issued-at, expiry, not-before and a unique ID added with one click, in seconds since 1970 as the standard requires.

Key generator

Fresh 2048-bit RSA, P-256/384/521 or Ed25519 key pairs, with the public JWK and JWKS ready for your config.

Strong secrets

Random HMAC secrets of the full hash length, so tokens can’t be cracked offline.

Verify instantly

Send the token and key to the debugger to check the signature and claims.

Local only

No server signs anything — safe for test keys, and nothing is logged.

Which algorithm should I use?

AlgorithmKeyUse it when
HS256One shared secret (32+ random bytes)The same service creates and checks the tokens
RS256RSA key pair (2048-bit or more)Others verify with your public key — the most widely supported choice
PS256RSA key pairYou want RSA with the more modern PSS padding
ES256EC P-256 key pairSmall, fast signatures with public-key verification
EdDSAEd25519 key pairModern, fast and hard to misuse, where your libraries support it

Good practice for tokens

  • Keep access tokens short-lived — minutes to an hour — and use refresh tokens for longer sessions.
  • Always set iss, aud and exp, and have servers check them along with the signature.
  • Put only what the receiver needs in the payload: it is readable by anyone who holds the token.
  • Use a random secret at least as long as the hash (32 bytes for HS256) and never commit it to source control.

FAQ

Frequently asked questions

Is it safe to sign tokens with my real keys here?

Signing happens entirely in your browser and nothing is sent or stored. For production keys, the safest habit is still to sign on your own servers; this tool is ideal for test and development tokens.

How long should a JWT secret be?

At least as long as the hash: 32 random bytes for HS256, 48 for HS384 and 64 for HS512 (RFC 7518). “Generate secret” creates one of the right length.

What format should the private key be in?

PEM is easiest: “BEGIN PRIVATE KEY” (PKCS#8), “BEGIN RSA PRIVATE KEY” or “BEGIN EC PRIVATE KEY” all work, as does a private JWK. Passphrase-protected keys must be decrypted first.

Why is exp a number like 1767229200?

JWT dates are seconds since 1 January 1970 UTC. The expiry buttons calculate it for you from the current time.

Can I create a token without a signature?

No. Unsigned tokens (alg “none”) can be forged by anyone, and secure libraries reject them, so this tool always signs.

Keep going

Browse every tool

Last updated Report a problem or suggest a feature