Skip to content
Allin

JWT Generator

Build and HMAC-sign a JSON Web Token in your browser — HS256, HS384 or HS512.

Open JWT Generator and you get an answer straight away, with no account to create. Its place is under Hashing & crypto; JWT decoder and Adler32 Checksum Calculator answer the questions closest to this one.

How to use it

  1. Open the tool — no signup or install needed.
  2. Enter your input or adjust the available options.
  3. Get your result instantly, then copy or download it.

Frequently asked questions

What does JWT Generator do?

Build and HMAC-sign a JSON Web Token in your browser — HS256, HS384 or HS512.

When would I actually use this?

Verifying a download matches its published checksum, comparing two files without reading them, and generating a signature for an API request.

What is the most common mistake?

Hashing a password with a fast algorithm. MD5 and SHA are built to be quick, which is exactly wrong for passwords — those need a deliberately slow function like bcrypt, scrypt or Argon2.

How is JWT Generator different from JWT decoder?

They sit next to each other but answer different questions: JWT decoder is the one to open when you need it to decode a JWT, read its claims and dates, and check its HMAC signature. Pick whichever matches what you're starting from — both are free.

Is there a tool for the next step?

Adler32 Checksum Calculator is the closest one after this: Generate a Adler-32 hash of any text instantly in your browser, with hex or Base64 output. Used in zlib and PNG.

What else is worth having open alongside it?

CRC32 Checksum Calculator and CRC64 Checksum Calculator — they come up in the same task often enough to be worth a second tab.

Where do the figures come from?

The digests follow their published specifications and are computed by the browser's own crypto implementation where one exists, so a value can be checked against any other conforming tool.

Further reading

All guides
ExplainerWhat Is Inside a JWT — and What It Does Not ProtectA JWT is signed, not encrypted. Anyone holding the token can decode the payload and read every claim in it. Here is a real token, decoded without any key, plus the three attacks the signature is supposed to stop and the one problem it cannot solve.ComparisonChecksums Are Not Hashes: CRC-32, Adler-32 and What They Are ForA checksum catches accidents. A cryptographic hash resists an attacker. A hash-table hash spreads keys. Three different jobs, three different families — and here is a CRC-32 collision constructed by hand in 0.11 seconds to show exactly why you cannot substitute one for another.ComparisonMD5, SHA-1, SHA-256: Which Hash, and For WhatMD5 is broken and MD5 is fine, depending on which of three security properties you needed. Here is what collision resistance, second-preimage resistance and preimage resistance actually mean, which algorithm still has which, and why none of them belongs near a password.ExplainerWhat Is a JWT (JSON Web Token)?A JWT is a compact, signed token used to carry identity between services. Here's its three parts, how it's used for auth, and its security limits.GuideWhat a Password Manager Cannot MeasureEntropy prices one attack: offline guessing against a stolen hash. Above roughly 90 bits the number stops deciding anything — and the meter on this site under-reported a random 20-character password in 300 draws out of 300.ExplainerPassword Entropy: What a Strength Meter Cannot KnowEntropy measures the process that produced a password, not the characters in it. H = L x log2(R) is only true when every character was chosen at random — which is exactly why a meter scoring a human-invented password on its character classes is measuring the wrong thing.