HS256 only. Your secret is processed locally in your browser and never uploaded. Do not use production secrets on shared devices.
About This Tool
JWT Encoder signs JSON Web Tokens with HS256 using the Web Crypto API entirely in your browser. Paste header and payload JSON, provide a secret, and get a compact JWT. Only HS256 is supported — no RS256 or private-key upload. Secrets never leave your device. Decode with Locly’s JWT Decoder to verify.
How to Use
- Edit header JSON (keep alg HS256)
- Edit payload JSON claims
- Enter your HMAC secret
- Click Encode & Sign
- Copy the token or verify it in JWT Decoder
Common Use Cases
- Dev: Quickly mint HS256 tokens for local APIs
- Debug: Reproduce tokens without posting secrets online
- Learning: Understand JWT header.payload.signature structure
- QA: Generate test tokens with known claims
- Offline: Sign tokens when you cannot use a backend