Apps / Security & Privacy Tools / JWT Signer & Verifier

🔏 JWT Signer & Verifier

Build and HMAC-sign a token from your own header/payload JSON, or verify a pasted token's signature and expiry against a secret. Runs entirely in your browser.

For local testing and debugging only. Never paste a real production signing secret, or a real user's token, here or into any online tool. Treat any secret you type into a browser tab as compromised.

1. Header & payload

Overrides the header's own "alg" when signing.

2. Signed token

Regenerates live as you edit the header, payload, algorithm or secret.

1. Token & secret

The algorithm is read from the token's own header (HS256/384/512 only — anything else is rejected).

2. Result

Paste a token and secret to verify.