JWT Encoder — Create & Sign JSON Web Tokens Online Free
Create and sign JSON Web Tokens with HS256, RS256, ES256 and more — 100% in-browser.
Jump to tool ↓Frequently Asked Questions
Creating Signed JWT Tokens
Signing a JWT involves three steps: (1) Base64URL-encode the header JSON specifying the algorithm, (2) Base64URL-encode the payload JSON containing your claims, (3) compute a cryptographic signature over header.payload using the secret or private key.
HMAC algorithms (HS256, HS384, HS512) use a shared secret key. Both the token issuer and verifier must know the same secret. This is common for single-server authentication.
RSA and EC algorithms (RS256, RS384, RS512, ES256, ES384, ES512) use asymmetric keys. The issuer signs with a private key; verifiers use only the public key. This is required for multi-service architectures, OIDC, and any scenario where token issuance and verification are separated.
Standards & References
Built and maintained by DevDecode. This tool processes your input in your browser; it is not uploaded for processing. Found an issue? Let us know.
Related Tools
Related Guides
'"audiences in jwt are not allowed" — Fix It'
Learn why you're seeing "audiences in jwt are not allowed" and how to fix JWT audience validation errors in your application.
AuthenticationJWT vs OAuth: What's the Difference?
JWT and OAuth are often confused — one is a token format, the other is an authorization framework. Here's exactly how they differ and how they work together.
AuthenticationJWT Tokens: Structure, Security & Best Practices
A deep dive into JSON Web Tokens — how they work, what the three parts mean, common vulnerabilities, and how to use JWTs securely in modern applications.