API TESTING
JWT Encoder
Build and sign JSON Web Tokens locally with HS256, HS384 or HS512, then verify the signature.
Security note: Use this only with throwaway secrets and test tokens. An HS256-signed JWT requires the server to share your secret, so never treat the token alone as proof of authenticity.
How it works
Each token has three dot-separated parts: a base64url-encoded header, a base64url-encoded payload, and a signature. The signature is an HMAC of the first two parts using your secret, keyed to the header's alg value.
QA uses
- Create test tokens with custom claims for authorization testing.
- Validate server behavior with a correct signature versus a tampered one.
- Generate expired-token fixtures by setting
expin the past. - Confirm your client handles both malformed and unsigned tokens.
To verify a token you did not generate here, paste the full token into the payload box. Decode and inspect any existing token with the JWT Decoder.