Skip to content
UniKit

JWT generator

Build a JWT from a custom payload: self-written base64url codec, iat / exp / nbf shortcuts, and HS256 / HS384 / HS512 signatures computed with the browser WebCrypto API — plus the decoded header, payload, signature segment and an expiry preview (RS256 / ES256 / none are explicitly unsupported).

Runs in your browserEvery computation happens in your browser — your data never leaves this device.

Payload and key

The base64url codec, claim assembly and signature concatenation are self-written; the HMAC signature is produced by the browser’s crypto.subtle after you click, entirely offline — the token is never uploaded.

Time claim shortcuts

Result

Fill in the payload and secret, then press Generate token.

What this tool does

  • No issuing service at hand while integrating? Generate a token here with the same payload and secret, then paste it into your API client to exercise the auth path.
  • Reproduce an incident: copy the payload of the failing token in (without the iat / exp shortcuts) and check whether the signature segment matches production — that tells you whether the key changed or the payload was altered.
  • Write examples for docs or front-end code: create a short-lived token with `exp` and read the remaining time so the sample does not expire before anyone uses it.
  • Learn the JWT structure: toggle iat, edit `kid`, and watch how the three segments change — much clearer than reading the spec.

Example

Input

Payload {"sub":"1234567890","name":"John Doe"}, secret your-256-bit-secret, algorithm HS256, iat unchecked and lifetime left empty

Output

eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIn0.Gfx6VO9tcxwk6xqx9yYzSfebfeakZp5JYIgP_edcw_A

This is the classic jwt.io example without the iat claim; the signature segment is byte-for-byte identical to createHmac("sha256", …) in Node.

Frequently asked questions

Why are RS256 and ES256 not supported?

Asymmetric signing needs a private key (PEM/JWK), and handing one to a web page is far riskier than it is useful — besides, those tokens are almost always issued server-side. So this tool sticks to the HMAC family: the secret can both sign and verify, which means anyone holding it can forge tokens, so treat HS* tokens as internal-only.

How is the signature computed?

The signing input is `base64url(header) + "." + base64url(payload)` signed with HMAC-SHA256 / 384 / 512 by the browser’s crypto.subtle after you press the button, exactly as RFC 7515 §5.1 defines it. Everything happens offline and the secret never leaves the page — but this is still a front-end tool, so avoid pasting production secrets on an untrusted machine.

What do iat, exp and nbf mean?

iat is issued-at, exp is expiry and nbf means “not valid before”, all expressed as Unix timestamps in seconds (RFC 7519 §4.1). When you use the shortcuts the tool writes current time plus the duration you entered and shows the absolute expiry and the remaining time, so you do not have to do the arithmetic yourself.

Why does the token change every time I generate it?

Because with iat checked or a lifetime filled in, the claims depend on the current time, so both the payload and the signature change. For a reproducible token — a test fixture, say — uncheck iat and clear the lifetime; with a fixed payload the output is fully deterministic.

Which lifetime formats are accepted?

`30m`, `1h`, `7d`, `2w`, `45s`, combinations such as `1h30m`, or plain seconds like `900`. The not-before field uses the same syntax and means “valid from now plus this delay”.

Keywords:jwtjson web tokenhs256hmactoken generatorjwt.ioJWT 生成令牌生成载荷签名base64url过期时间

Related tools