About the JWT Encoder
A JWT (RFC 7519) is built from three Base64url parts joined by dots: the JSON header, the JSON payload of claims, and the signature. The encoder serialises the header and the payload without whitespace, encodes each as Base64url without padding, and signs header.payload as a JWS (RFC 7515) using the Web Crypto API.
The algorithm is taken from the alg field of the header; picking another one in the list rewrites the header for you. HS256, HS384 and HS512 are HMACs with a shared secret, typed as text or given as Base64. RS256/384/512 (RSA PKCS#1 v1.5) and PS256/384/512 (RSA-PSS) sign with an RSA private key, ES256/384/512 with an elliptic-curve key on P-256, P-384 or P-521; ECDSA signatures are written as the raw r‖s pair that JWS requires, not as DER. Paste the private key as PKCS#8 PEM or JWK — PKCS#1 and SEC1 PEM are converted on the fly — or click “Generate key pair” for a fresh test key. The matching public key is shown for the verifier.
Use it to produce tokens for tests, Postman or curl requests and local development. The payload of a JWT is only encoded, not encrypted: anyone holding the token can read it, so never put passwords or other secrets in the claims. The buttons above the payload set iat to the current time and exp to one hour from now, both in Unix seconds.
How to use it
- Edit the header and the payload as JSON.
- Pick the algorithm, then type the secret (HS*) or paste a private key (RS*, PS*, ES*) — or generate a key pair.
- Use “iat = now” and “exp = +1h” to set fresh time claims.
- Copy the token, and the public key if the verifier needs it.
Frequently asked questions
Is my secret or private key sent anywhere?
How long should the secret be?
Why is my token different every time, or from another tool's?
Which private key formats are accepted?
BEGIN PRIVATE KEY) and JWK. PKCS#1 (BEGIN RSA PRIVATE KEY) and SEC1 (BEGIN EC PRIVATE KEY) are converted automatically. Encrypted keys must be decrypted first: openssl pkey -in enc.pem -out key.pem.