More
More
JWT Encoder: Sign a Test Token
Write the header and payload as JSON, type a development secret, and the signed token appears as you type.
Free tools that run in your browser. Nothing you type, open or create is uploaded to NerdBible or anyone else.
Never paste production tokens or production secrets into any website. A valid token is a key to an account until it expires, and a signing secret lets anyone mint tokens your servers will trust. This page works in your browser and sends nothing, but the safe habit is to use expired tokens and development secrets only.
Paste a token to read it.
| Claim | Value | Meaning |
|---|
How to use it
- Paste a JWT. A leading Bearer is removed for you.
- Read the decoded header and payload, and the claims table with dates in your time zone and UTC.
- Check the status line to see whether the token has expired or is not valid yet. For an HS256, HS384 or HS512 token you can type a development secret to check the signature.
- To make a test token, open Encoder, edit the header and payload JSON, choose the algorithm and type a development secret. The signed token appears below, ready to copy or open in the decoder.
Questions
How do I create a JWT for testing?
Edit the header and payload JSON, pick HS256, HS384 or HS512, type a test secret and copy the token. Set iat and exp from now adds standard time claims.
Can it make RS256 tokens?
No. It signs with shared-secret HMAC only (HS256, HS384, HS512). RS256 and ES256 need a private key and are not supported.
Is a JWT payload encrypted?
No. A signed JWT is only encoded, so anyone can read the claims. The signature proves it was not changed; it does not hide anything.
About this tool
Building a token by hand
A JSON Web Token has three parts separated by dots: a Base64URL encoded header, a Base64URL encoded payload and a signature. The encoder signs the first two with HMAC using your browser's Web Crypto API.
- Algorithms. HS256, HS384 and HS512, the shared-secret algorithms. Tokens signed with a private key, such as RS256 or ES256, are not created here.
- Time claims. Set iat and exp from now fills in the issued time and an expiry one hour later, as Unix timestamps in seconds.
- Base64URL secrets. Tick the option if your system stores the secret encoded, so it is decoded to raw bytes before signing.
- Check it. Paste the result into the Decoder tab to read it back and verify the signature.
Test secrets only
Use this for local development, debugging and writing tests. Never type a production signing secret into a website, this one included: anyone holding it can mint tokens your servers will accept. Remember too that the payload is only encoded, not encrypted, so anyone with the token can read every claim.
Related tools
- Base64 Encode & DecodeEncode and decode Base64 text.
- Hash Generator & File ChecksumSHA and MD5 hashes of text or files, HMAC signatures, and checking a download against its published checksum.
- Unix Timestamp ConverterTimestamps to dates and back, in any time zone.
- JSON Formatter & ValidatorPretty-print, minify and validate JSON.