Generate signed JSON Web Tokens (JWT) with custom headers, payloads, expiration times, and HMAC-SHA256 secret keys for testing and mock APIs.
Add custom claims, roles, user IDs, and permissions with syntax-highlighted JSON editing.
Quickly set expiration timestamps for 1 hour, 24 hours, 7 days, or custom durations.
Signs tokens in browser memory using Web Crypto HMAC-SHA256 with your secret key.
Generate test tokens and secret keys with zero cloud logging or network exposure.
The JWT Generator takes your Header and Payload JSON objects, serializes them to UTF-8 strings, and encodes them using URL-safe Base64 (base64url).
It concatenates the encoded parts with a dot delimiter (header.payload) and feeds the string along with your secret key into crypto.subtle.sign("HMAC", ...).
The resulting binary HMAC-SHA256 signature is encoded to base64url and appended, producing a fully compliant RFC 7519 JSON Web Token.
Generate signed mock tokens for Postman collections, Jest unit tests, and Cypress E2E test runs.
Create tokens with "role": "admin" vs "role": "viewer" to verify authorization middleware.
Generate pre-expired tokens to verify that your frontend auth guards refresh tokens correctly.
Issue test access tokens when developing microservices without spinning up an identity provider.
Yes. Tokens generated by Softnag are fully compliant with RFC 7519 and work with jsonwebtoken (Node.js), PyJWT (Python), jjwt (Java), and Go-jwt.
No. HMAC cryptographic signing is computed entirely in your browser using the native Web Crypto API.
Yes. You can use the expiration helper to configure lifetime in minutes, hours, days, or custom timestamps.
Yes. You can edit the JSON payload directly to include any custom fields your application requires.
The generator currently supports standard HS256 (HMAC with SHA-256), the most widely used symmetric algorithm.
Yes! It generates standard RFC 7519 compliant JSON Web Tokens.