This tool builds a JWT from a header, payload and secret, and signs it with HMAC-SHA256/384/512 using your browser's native Web Crypto API. The secret never leaves your machine — nothing is sent to a server.


The algorithm you pick determines both the alg claim in the header and which HMAC hash function signs the token. The same secret must be used to verify it later — decode it with the JWT Decoder (decoding doesn't require the secret; verifying the signature would, and this tool doesn't check signatures).

Frequently asked questions

Is my secret key sent anywhere?

No — the token is signed entirely in your browser using the Web Crypto API. The secret, payload and resulting token never leave your machine.

Which algorithms are supported?

HS256, HS384 and HS512 — symmetric algorithms where the same secret both signs and verifies the token. Asymmetric algorithms (RS256, ES256) need a key pair and are out of scope for this tool.

Can I use this to generate a real production token?

Yes, for HMAC-based tokens — the signature is computed the same way a server library would. Just don't reuse a throwaway secret you typed here for anything real, and never share a token's secret.

Related tools

Bcrypt Generator & Checker — Hash a password with bcrypt or verify it against a hash
Open Graph Preview — Preview a page's Open Graph and Twitter meta tags
Browser AI Tester — Test Chrome's built-in on-device AI APIs right in your browser
DNS Lookup — Query A, AAAA, MX, TXT, NS, SOA and CAA records for a domain


Main page