Header
Payload
Quick-add claims:
Signature
19 chars
Token will appear here…

💡 Tips

HMAC Algorithms

HS256 uses SHA-256 (128-bit key recommended).
HS384 uses SHA-384 (192-bit key recommended).
HS512 uses SHA-512 (256-bit key recommended).

Security

Never use weak or guessable secrets. JWTs are signed but not encrypted — anyone can read the payload. Use JWE if you need confidentiality.