JWT Builder: On-Device Test Token Guide
Learning token structure for API tests needs a safe builder. This tool signs header and payload with HS256/384/512 on your device; secrets never leave. TEST ONLY; never paste production secrets.
Step by step
- Write the header JSON, e.g. alg HS256.
- Write the payload JSON with subject and name.
- Type a temporary secret, pick the algorithm.
- Generate and inspect the three-part token.
- Decode it, verify content, delete the secret.
Example scenario
A student writes sample header and payload, picks HS256 with a temporary secret. A three-part token appears; decoding shows the name. The secret is deleted, never used in production.
Check your result
Confirm three parts with two dots. Match content to input. Wipe the secret from notes. Rotate any production secret ever pasted.
Frequently asked questions
Token parts?
Header, payload and signature dot-separated.
Why test only?
Browser demos teach structure; production signs server-side.
Which algorithm?
HS256 is common; all three are symmetric.
Where is the secret?
In-memory only, never sent; still delete it.
Verify fails?
Secret or content changed slightly.
Keep an original copy before processing your file. Examples are illustrative; results depend on your document.