JWT Signer

JWT Signer

Build a signed test JWT locally with HMAC Web Crypto. Signing does not grant authorization or prove token ownership.

Signing controlsCreate a compact JWT with a local HMAC secret
JWT headerJWT metadata; alg and typ are normalized on signing
JWT payloadClaims to include in the signed token

Add a JSON header, payload, and synthetic secret to create a signed JWT.

Use synthetic secrets and claims for testing. A valid signature does not make a token trusted or authorized.

Copy JWT signing codeEnvironment variables keep credentials out of copied code
import { createHmac } from "node:crypto";

const header = { alg: "HS256", typ: "JWT" };
const payload = { sub: "user-1001" };
const base64url = (value) => Buffer.from(JSON.stringify(value)).toString("base64url");
const signingInput = `${base64url(header)}.${base64url(payload)}`;
const signature = createHmac("sha256", process.env.JWT_HMAC_SECRET ?? "").update(signingInput).digest("base64url");
console.log(`${signingInput}.${signature}`);