JWT Encoder

JWT Encoder

Sign an HS256, HS384, or HS512 JWT locally from a JSON payload and secret.

Free
No signup
Instant
Private

1. Enter payload JSON

2. Enter your secret

3. Select algorithm

HS256 is HMAC-SHA-256 — the usual JWT algorithm.

4. JWT Result

HS256

eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0IiwibmFtZSI6IkFkYSJ9.SzCjpzFeD6ddLmU1inAKrppU47C7FpgRdxmIq5mCLVg
117 characters

All Algorithms

AlgorithmTokenActions
HS256eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0IiwibmFtZSI6IkFkYSJ9.SzCjpzFeD6ddLmU1inAKrppU47C7FpgRdxmIq5mCLVg
HS384eyJhbGciOiJIUzM4NCIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0IiwibmFtZSI6IkFkYSJ9.IzvGGvOfPjA1yyU00sq9kf6qvhIyLrZgtF8RsShjk4KefCQw_Emb-x9AQnGPrtej
HS512eyJhbGciOiJIUzUxMiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0IiwibmFtZSI6IkFkYSJ9.6KKYv3f9Mm1Eh7Rk6I3i4LyCX9Ieg2x6fGYCNLy9Oz9BDdp8XAsAf1nZIGiKqEf51hOh272FJnWyO6BLf9Sz7A

About JWT encoding

A JWT is a header, payload, and HMAC signature joined by dots. HS256, HS384, and HS512 sign the token with a shared secret in this browser using Web Crypto. The payload must be valid JSON; we reject it before signing. The All Algorithms table signs the same claims with every HMAC option so you can compare tokens without re-pasting the secret. Generate random fills a hex key for experiments — do not ship that key. Show key reveals the field; we do not persist the secret.

Encoding is not access control by itself. Anyone who can decode the payload can read sub and exp; the signature only proves the producer knew the secret. JWT Decoder on this site does not verify. RSA and ECDSA are out of scope here. Keep production secrets off shared machines. This is a debugger, not an IdP. Related: HMAC Generator for a raw keyed digest, Hash Generator when you have no key, bcrypt when the secret is a password to store.

Your data stays private

Everything is processed locally in your browser. We never upload or store your data.

Learn more about privacy →

Common use cases

Authentication

Issue a signed token for a session or API client.

APIs

Pass claims between services without a server round-trip on this page.

Claims

Encode sub, name, and other JSON fields into a compact token.

Local signing

Sign tokens in this tab for debugging — nothing is uploaded.

Secrets

Do not paste production keys on a shared computer.

How to encode a JWT

Paste claims

Enter a JSON payload. Invalid JSON is rejected before signing.

Enter the secret

Use the HMAC secret. Generate random fills a hex key. Show key reveals the field.

Choose HS256, HS384, or HS512

HS256 is the usual JWT algorithm. The table signs the same payload with every HMAC option.

Copy the token

Copy, download, or share the three-part JWT. Keep production secrets off shared machines.

Related developer tools

JWT Encoder FAQ

Paste JSON claims, enter a secret, choose HS256 (or HS384/HS512), and generate. The token is signed in your browser. The All Algorithms table signs the same payload with every HMAC option.

JWT Decoder only displays header and payload. Encoder can sign with HMAC. Keep production secrets off shared machines.