JWT Encoder
Sign an HS256, HS384, or HS512 JWT locally from a JSON payload and secret.
1. Enter payload JSON
2. Enter your secret
3. Select algorithm
4. JWT Result
HS256
All Algorithms
| Algorithm | Token | Actions |
|---|---|---|
| HS256 | eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0IiwibmFtZSI6IkFkYSJ9.SzCjpzFeD6ddLmU1inAKrppU47C7FpgRdxmIq5mCLVg | |
| HS384 | eyJhbGciOiJIUzM4NCIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0IiwibmFtZSI6IkFkYSJ9.IzvGGvOfPjA1yyU00sq9kf6qvhIyLrZgtF8RsShjk4KefCQw_Emb-x9AQnGPrtej | |
| HS512 | eyJhbGciOiJIUzUxMiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0IiwibmFtZSI6IkFkYSJ9.6KKYv3f9Mm1Eh7Rk6I3i4LyCX9Ieg2x6fGYCNLy9Oz9BDdp8XAsAf1nZIGiKqEf51hOh272FJnWyO6BLf9Sz7A |
About JWT encoding
A JWT is a header, payload, and HMAC signature joined by dots. HS256, HS384, and HS512 sign the token with a shared secret in this browser using Web Crypto. The payload must be valid JSON; we reject it before signing. The All Algorithms table signs the same claims with every HMAC option so you can compare tokens without re-pasting the secret. Generate random fills a hex key for experiments — do not ship that key. Show key reveals the field; we do not persist the secret.
Encoding is not access control by itself. Anyone who can decode the payload can read sub and exp; the signature only proves the producer knew the secret. JWT Decoder on this site does not verify. RSA and ECDSA are out of scope here. Keep production secrets off shared machines. This is a debugger, not an IdP. Related: HMAC Generator for a raw keyed digest, Hash Generator when you have no key, bcrypt when the secret is a password to store.
Your data stays private
Everything is processed locally in your browser. We never upload or store your data.
Common use cases
Authentication
Issue a signed token for a session or API client.
APIs
Pass claims between services without a server round-trip on this page.
Claims
Encode sub, name, and other JSON fields into a compact token.
Local signing
Sign tokens in this tab for debugging — nothing is uploaded.
Secrets
Do not paste production keys on a shared computer.
How to encode a JWT
Paste claims
Enter a JSON payload. Invalid JSON is rejected before signing.
Enter the secret
Use the HMAC secret. Generate random fills a hex key. Show key reveals the field.
Choose HS256, HS384, or HS512
HS256 is the usual JWT algorithm. The table signs the same payload with every HMAC option.
Copy the token
Copy, download, or share the three-part JWT. Keep production secrets off shared machines.
Related developer tools
JWT Decoder
Decode a JWT header and payload in your browser as you type. The signature is displayed but not verified. Invalid tokens are not saved.
HMAC Generator
Generate HMAC (Hash-based Message Authentication Code) using various algorithms. HMAC is commonly used to verify the integrity and authenticity of messages.
Hash Generator
Generate SHA-1, SHA-256, SHA-384, or SHA-512 hashes using various encodings. Hashing is commonly used to verify integrity and fingerprint data.
Bcrypt Hash / Verify
Hash a password with bcrypt, or verify a password against an existing hash — locally in your browser.
UUID Generator
Generate UUIDs instantly in your browser. Free, private, and no signup required.
JWT Encoder FAQ
Paste JSON claims, enter a secret, choose HS256 (or HS384/HS512), and generate. The token is signed in your browser. The All Algorithms table signs the same payload with every HMAC option.
JWT Decoder only displays header and payload. Encoder can sign with HMAC. Keep production secrets off shared machines.