How to create a signed JWT online
Build an HS256/HS384/HS512 JWT from a JSON payload and secret in your browser.
Encode vs decode
JWT Decoder inspects an existing token. JWT Encoder builds a new one: header, JSON payload, and an HMAC signature using your secret. The secret stays on your device.
Steps
1) Open JWT Encoder at /tools/jwt-encoder. 2) Choose HS256 (typical). 3) Enter the signing secret. 4) Paste payload JSON. The token updates as you type — there is no Run button on the article page. Copy the token. Do not use production secrets on a shared computer. The secret is not persisted.
Worked example
Payload {"sub":"1234","name":"Ada"} plus a throwaway secret mints three Base64URL segments. Decode it on JWT Decoder at /tools/jwt-decoder — decode is not verify. HMAC Generator signs a raw body without JWT headers. RSA and ECDSA are not offered here. Invalid JSON is rejected before signing.
Privacy
Secrets stay in the tab. Related: /tools/jwt-decoder, /tools/hmac-generator. See also the decode-and-sign how-to for the longer story.
Common mistakes
Minting HS256 with a production secret on a shared laptop leaks the key via the screen and maybe the clipboard. Encoder does not add exp unless you put it in the JSON. Decoder will read the token without proving the signature. RSA alg values in the header are not offered — this page is HMAC only. Invalid JSON payload is rejected. Related longer walk: /guides/how-to-decode-and-sign-jwts. Close the tab after copying a throwaway token.