# JWT Sign (HS256 / RS256)

> Sign a JSON Web Token with HS256 (HMAC shared secret) or RS256 (RSA private key). Output is a standard compact JWT (header.payload.signature).

URL: https://uttir.com/jwt-sign
Categories: security-tools, developer-tools, encoding-tools
Privacy: Signing runs entirely in your browser. The HMAC secret and RSA private key never leave this device.

## About

A JSON Web Token (JWT) is three base64url segments: header.payload.signature. The header says which algorithm to use; the payload is your claims; the signature is the HMAC or RSA signature over the first two segments.

This tool builds the header and payload in the browser, then signs with Web Crypto (HMAC for HS256, RSASSA for RS256). Nothing is sent to a server.

## How to use

1. **Pick the algorithm** — HS256 is a shared secret; pick it if both sides have the same secret. RS256 is asymmetric; pick it if the verifier only has a public key.
2. **Add claims** — Standard claims: sub (subject), iss (issuer), aud (audience), exp (expiration, Unix seconds), iat (issued at). Or add your own custom claims.
3. **Provide the key** — HS256: a shared secret string. RS256: paste a PKCS#8 PEM private key (including the BEGIN / END lines).

## FAQ

### Is the key sent anywhere?

No. Signing is local; the secret / private key stays in your browser. (You can verify this with the network panel open.)

### Can I generate RS256 keys here?

Yes — use the RSA Key Generator tool to make a PSS-capable keypair, then paste the private key (PEM) into this tool.

### How do I decode the result?

Use the existing JWT Decoder tool — paste the token in, see the header, payload, and signature broken out.

## Related tools

- [JWT Decoder](https://uttir.com/jwt-decoder) — Decode a JWT’s header and payload and check its expiration — without sending it anywhere.
- [HMAC Generator](https://uttir.com/hmac-generator) — Compute a Hash-based Message Authentication Code (HMAC) for any message and shared secret. Supports SHA-256, SHA-512, SHA-1, and MD5. All computation runs in your browser.
- [JSON Formatter](https://uttir.com/json-formatter) — Format, beautify, and validate JSON with adjustable indentation — instantly in your browser.

---

For the full HTML page with the live tool, visit https://uttir.com/jwt-sign.
This file is the markdown rendering at https://uttir.com/jwt-sign.md. See https://uttir.com/llms.txt for a site-wide summary.
