🔏 JWT Signer & Verifier
Build and HMAC-sign a token from your own header/payload JSON, or verify a pasted token's signature and expiry against a secret. Runs entirely in your browser.
For local testing and debugging only. Never paste a real production signing secret,
or a real user's token, here or into any online tool. Treat any secret you type into a browser tab
as compromised.
1. Header & payload
Overrides the header's own "alg" when signing.
2. Signed token
Regenerates live as you edit the header, payload, algorithm or secret.
1. Token & secret
The algorithm is read from the token's own header (HS256/384/512 only — anything else is rejected).
2. Result
Paste a token and secret to verify.