CanDoYa
ZH-TW

免費 JWT 產生器

全程在瀏覽器裡執行,免上傳、免註冊。

Use this for local testing. Do not paste production secrets into tools you do not control.

Generated token
Edit the header and payload to generate a token
分享這個工具

JWT 產生器有什麼用?

JWT 產生器會依照標頭、負載聲明與簽署方式建立精簡的 JSON Web Token。此工具可用瀏覽器 Web Crypto 產生 HS256 權杖,也可產生除錯用的未簽署權杖,不會把 JSON 或密鑰送到伺服器。

使用方式

  1. 1Edit the header. Keep typ as JWT and choose HS256 or none.
  2. 2Add payload claims. Write a JSON object with sub, iat, exp or custom claims.
  3. 3Enter a 密鑰. For HS256, use only throwaway development values.
  4. 4Copy the token. Copy the generated compact JWT from the output box.

適合誰用

JWTs are compact URL-safe strings used in Authorization headers, callbacks and test fixtures. This tool follows the JWS compact form: base64url header, base64url payload and a signature segment separated by dots. Use it as a development helper, not as production key management.

常見問題

Is JWT 產生器 free?

Yes. You can use this JWT generator without sign-up, account or usage limit.

Are my claims or secrets uploaded?

No. The JSON and HS256 secret are processed in the browser. For real systems, keep production signing keys in your own server or key-management environment.

Can I use this for production authentication?

Use it for local testing and examples. Production authentication also needs issuer checks, audience checks, expiry validation, replay controls, key rotation and secure storage.

Which algorithms are supported?

This version supports HS256 and the none algorithm for unsigned debugging tokens. It does not sign RS256, ES256 or private-key JWTs.

What is the none algorithm?

The none algorithm creates an unsigned JWT with an empty signature segment. It is useful only for debugging when a test system explicitly accepts it.

Why does the header alg change?

The selected algorithm button controls the real output, so the generator rewrites alg to HS256 or none to match the token it creates.