Developer secret

JWT Secret Generator

Generate a cryptographically random shared secret sized for HS256, HS384, or HS512. The secret is created locally and never sent to this site.

Generate a JWT HMAC secret

Choose the JWT HMAC algorithm and the text encoding expected by your application.

Used only by the “Copy .env line” button.

256 random bits43 encoded charactersBase64URL without padding
Generated locallyThe raw random bytes and encoded secret remain in this browser tab.

How long should a JWT secret be?

RFC 7518 requires an HMAC key at least as large as the hash output: 256 bits for HS256, 384 bits for HS384, and 512 bits for HS512. The presets above generate exactly those minimum byte lengths.

Base64URL, Base64, or hexadecimal?

All three options represent the same random bytes; encoding changes the text, not the entropy. Base64URL removes padding and avoids the + and / characters, which makes it convenient in configuration files and URL-safe contexts. Use the encoding expected by your JWT library.

A JWT secret is not a finished token

This tool creates key material for an HMAC signing configuration. It does not create a JWT header or payload, sign a token, validate claims, choose expiration rules, or manage rotation. Those decisions belong in the application and its authentication design.

Storage and rotation

Keep the secret outside the repository, restrict who and what can read it, and plan a rotation process. Replacing a live secret immediately invalidates tokens signed only with the previous value unless the application supports an overlap period or multiple verification keys.

Sources and technical basis

The algorithm sizes follow RFC 7518 section 3.2. Random bytes come from the browser’s Web Crypto getRandomValues API. This page generates symmetric HMAC secrets only; it does not generate RSA or elliptic-curve keypairs.

Related developer tools

Random key generator creates generic 128-, 192-, or 256-bit material. Random string generator creates customizable test strings and identifiers. Use the JWT tool when the consuming JWT algorithm determines the required HMAC key size.