Web Tools DocGuides

How to use JWT Encoder (HS256)

Get the best out of JWT Encoder (HS256): every option explained, a worked example, and what to check when the output is not what you expected.

Updated July 31, 2026

What it does

Create and sign custom JSON Web Tokens (JWT) using HS256. It runs entirely in your browser — your input never leaves your device.

Options

Every setting this tool exposes, straight from the code that validates it.

OptionTypeDefaultWhat it does
headertext{"alg":"HS256","typ":"JWT"}JWT header JSON (HS256 only). Defaults to {"alg":"HS256","typ":"JWT"}.
payloadtextJWT payload/claims JSON. Required.
secrettextHMAC signing secret. Accepts at least 1 characters. Required.

Example

Try it with these settings on the tool page:

  • header: {"alg":"HS256","typ":"JWT"}
  • payload: example
  • secret: my-secret

Getting the result you want

Most of the control here is in the options above. If the output is not what you expected, the setting to check first is header — those change the shape of the output rather than the input it accepts.

Troubleshooting

  • Nothing happens / the output stays empty. payload, secret are required — the tool waits until you provide them.
  • A value is rejected. secret accepts at least 1 characters. Anything outside that is refused rather than silently clamped.
  • It is slow on very large input. Everything runs in your browser, so speed depends on your device. Very large inputs are best split up, or run through the API where the work happens on our servers.

Automating it

The same logic is available as a REST endpoint, so you can run it from a script, a CI job or your own app.

Bash
curl "https://api.toolsxpo.com/v1/jwt-encoder" \
  -H "Authorization: Bearer $TOOLSXPO_KEY"

It costs 1 credit per successful call. See the full endpoint reference, or try it in the playground.

Tools covered here

JWT Encoder (HS256)

Security

security

Related