What this does
Writes a JSON Web Token from a header and a payload you edit, then signs it. Use it to produce test tokens for an API, reproduce a bug with a specific claim, or learn how each algorithm family looks.
Algorithms and keys
- HS256, HS384, HS512: sign with a shared secret, given as text, Base64, or hex.
- RS256/384/512 and PS256/384/512: sign with an RSA private key as PKCS#8 PEM (
BEGIN PRIVATE KEY) or a private JWK. - ES256, ES384, ES512: sign with an elliptic curve key on P-256, P-384, or P-521.
- EdDSA: sign with an Ed25519 key.
"Generate" creates a fresh secret or key pair for the chosen algorithm and shows the matching verification key so you can check the token in the JWT decoder. Keys from older tools in PKCS#1 form (BEGIN RSA PRIVATE KEY) must be converted first with openssl pkcs8 -topk8 -nocrypt. The algorithm none is not offered because it produces unsigned tokens.
Claim helpers
"Set exp" computes the expiry from the current time plus the lifetime you pick, and the iat, nbf, and jti buttons add the matching claim. The page also warns about missing expiry, very long lifetimes, and short HMAC secrets as you edit.
Example
Keep the default header, press "Set exp" with 15 minutes, press "Generate secret", then "Sign token". Copy the result or open it directly in the decoder.
Privacy
Signing happens in your browser with the Web Crypto API. Your keys and payload are never uploaded or stored, and they are gone when you close the tab. Use throwaway keys for tokens you share, and never paste a production signing key into any website.