JWT Generator
Create HS256 test JWTs or unsigned none tokens
Enter the payload and secret first to generate a JWT; the header is fixed, with HS256 or unsigned none. Advanced mode provides scenario presets.
The full guide also includes pitfalls, worked examples, snippets, FAQs, and related tools for checking results or troubleshooting.
About this tool
Create a compact JWT from a JSON object using HS256 or the unsigned none option. The Header is fixed to the selected alg and typ: JWT; the secret is used as UTF-8 text, without Base64 or hex decoding. Generated claims are not checked against a server policy. Inputs and results stay in memory, and opening the page removes the old secret/payload draft. Use public test fixtures for debugging; issue production credentials within your application’s controlled signing system.
Production Snippets
A reproducible HS256 token checked with Node.js
text
Algorithm: HS256
Secret (UTF-8 text, public test key): toolskit-public-test-key-32-bytes!
Payload: {"sub":"demo"}
Expected token:
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiJkZW1vIn0.QbFoHZpyPTQMOX7-Zw5xSs1N_BXJdWPM5ZMhN9RrUwI
No exp is added automatically. Do not use this published key for real credentials.Frequently Asked Questions
Can I edit the header or use HS384, HS512, or RSA?
No. The supported choices are HS256 and none. Header fields are fixed to alg and typ: JWT; there is no custom kid or header editor. Adding kid to the Payload creates a claim, not the header field used for key selection.
How is the HS256 secret interpreted?
Exactly as UTF-8 text, including leading or trailing spaces once the nonblank input check passes. A Base64 or hex-looking string is not decoded. Use the same key bytes at verification. Public example keys are for tests; production HS256 needs a high-entropy key with at least 256 bits, protected by the application.
What Payload input is accepted?
A JSON object. null, arrays, numbers, and other JSON root types are rejected. The object is parsed and serialized compactly before signing. exp, nbf, iat, iss, and aud are not automatically generated, checked, or corrected by the tool.
What does the none option produce?
An unsigned token with alg: none and an empty third segment, so it ends in a dot. It is useful for inspecting a test format, not proof of identity. A service must not accept an unsigned token merely because it can be decoded.
Are the signing secret and Payload saved?
No. The tool neither uploads these inputs nor saves them as a browser draft. Opening the page removes the legacy localStorage draft. Editing inputs or clearing the tool invalidates pending generation and removes the displayed result.
Why can the server still reject a generated HS256 token?
The server may expect another algorithm, different key bytes, a supported key ID, different claims, or a different time window. The decoder can inspect claims but cannot verify a signature. Test the signature and the receiving application’s issuer, audience, time, and authorization rules separately.
Keep browsing