Skip to content

Encodeurs & Crypto

Créateur JWT (HS256)

Sign a JWT with HMAC-SHA256 — in your browser.

Runs in your browser

Note de la rédaction

Understanding · A signature, not a secret.

Ce chapitre approfondi n'est actuellement disponible qu'en anglais. L'outil de conversion ci-dessus fonctionne dans votre langue ; le long article explicatif n'a pas encore été traduit.

Questions fréquentes

Quick answers.

Is my secret key safe?

Yes. The hashing and signature generation take place entirely within your browser using the Web Crypto API. Your secret key is never sent to our servers.

What is HS256?

HS256 stands for HMAC with SHA-256. It is a symmetric signing algorithm, meaning the same secret key is used to both create the signature and verify it later.

Why is the output divided into three parts?

A JWT consists of a header, a payload, and a signature, each separated by a dot. They are Base64Url encoded to ensure they can be safely transmitted in HTTP headers or URLs.

Can I use this for production tokens?

While technically valid, this tool is intended for debugging and development testing. For production environments, you should use standard libraries to automate token generation within your application code.

Les internautes recherchent aussi

Outils similaires

More in this room.

Tout voir dans Encodeurs & Crypto