🔒 Runs in your browser — nothing is uploaded✓ Free, no signup
JWT Generator — Create & Sign JSON Web Tokens
Write your claims, choose HS256, HS384 or HS512, and get a signed JWT instantly. Add iat and exp with one click to test token expiry.
Header · Payload · Signature
Paste the token into the JWT Decoder to inspect it.
When should you use the JWT Generator?
- Testing a protected API endpoint without logging in through the real auth flow
- Checking how your backend handles expired tokens or missing roles
- Creating fixture tokens for automated tests
How to use the JWT Generator
- 1
Choose an algorithm
HS256 is the most widely supported. Use the same algorithm your server expects.
- 2
Edit the payload
Change the claims in the JSON editor. Use the iat, exp +1h, exp +24h and expired buttons to set timestamps.
- 3
Enter the secret
Use the same secret your server verifies with, or click Generate random secret. Tick Base64 if your secret is Base64-encoded.
- 4
Copy the token
The token updates as you type. Copy it and send it as Authorization: Bearer <token>.
Examples
Payload to signed token
Payload (HS256, secret “abc”)
{
"sub": "1",
"name": "Ada"
}Token
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9 .eyJzdWIiOiIxIiwibmFtZSI6IkFkYSJ9 .isELjoOcNdKnCkXHJJBSZ4BNCo5SaLUptSrRhILmkHY
Common errors and how to fix them
invalid signature (from your API)- The secret or algorithm differs from the server's. Check for trailing spaces, and whether the server's secret is Base64-encoded.
jwt expired- exp is in the past. Click exp +1h to refresh it. Remember exp is in seconds, not milliseconds.
jwt not active- The token has an nbf (not before) claim in the future. Remove it or set it to the current time.
Payload must be a JSON object- The payload has to be a JSON object { ... }, not an array or a plain string.
Explore More Developer Tools
Format, Validate, and Generate Data Instantly
TrueFormatter provides essential utilities for modern web development, including JSON formatting, YAML conversion, and more.
JSON Auto-Fixer & Formatter
Repair, validate, and beautify broken JSON (missing quotes, trailing commas).
JSON Validator & Linter
Check JSON syntax and see the exact line and column of every error.
JSON Beautifier
Pretty-print and indent JSON for easy reading and debugging.
JSON Compare & Diff Tool
Find the difference between two JSON objects visually and quickly.
JSONPath Tester
Evaluate JSONPath expressions with filters and recursive queries.
JSON Schema Generator
Generate a JSON Schema from any sample JSON document.
JSON to CSV Converter
Flatten nested JSON arrays into CSV for spreadsheets.
YAML ⇆ JSON Converter
Convert YAML to JSON or JSON to YAML instantly.
JWT Decoder
Decode and inspect JSON Web Tokens (JWT) Header and Payload.
JWT Generator
Create and sign HS256/HS384/HS512 JSON Web Tokens for testing.
Hash Generator (MD5, SHA)
Generate MD5, SHA-1, SHA-256, SHA-384 and SHA-512 hashes.
Base64 Encoder ⇆ Decoder
Encode text to Base64 and decode Base64 to text for API debugging.
URL Encoder & Decoder
Cleanly encode special characters in URLs and decode query strings.
SQL Formatter & Beautifier
Format SQL queries for MySQL, PostgreSQL, SQL Server, SQLite and more.
CSS Minifier & Compressor
Optimize CSS by removing whitespace and comments to accelerate page load time.
JS Minifier & Compressor
Compress JavaScript to improve website speed and performance.
Regex Tester & Debugger
Test JavaScript regular expressions with live match highlighting and groups.
Cron Expression Generator
Build cron schedules, read them in plain English and preview next runs.
UUID / GUID Generator
Generate unique V4 UUIDs for database keys or testing.
Epoch converter online
Convert UNIX timestamps to human-readable dates and back instantly.
Crop Image Online
Crop images exactly as selected with fixed aspect ratios. No upload, no resize, no quality loss.
Compress Image Online
Compress JPG, PNG & WebP images directly in your browser. No upload, no tracking, instant download.
JWT Generator FAQ
It creates signed JSON Web Tokens so you can test APIs, mock authentication, or check how your backend handles specific claims, expired tokens or roles.
HS256, HS384 and HS512 — HMAC with SHA-256, SHA-384 or SHA-512 using a shared secret. These are the most common algorithms for testing and for services that share one secret.
At least as long as the hash output: 32 bytes for HS256, 48 for HS384 and 64 for HS512 (RFC 7518). Use Generate random secret to get a strong 32-byte key.
Common registered claims are sub (subject/user id), iat (issued at), exp (expiry), nbf (not before), iss (issuer) and aud (audience). Times are Unix timestamps in seconds.
Click the 'expired' button. It sets exp to one minute ago so you can test how your API rejects expired tokens.
No. A signed JWT is only Base64URL-encoded, so anyone can read the payload. The signature prevents tampering, not reading. Never put passwords or secrets in the payload.
