How long should a JWT secret be?
RFC 7518 requires an HMAC key at least as large as the hash output: 256 bits for HS256, 384 bits for HS384, and 512 bits for HS512. The presets above generate exactly those minimum byte lengths.
Base64URL, Base64, or hexadecimal?
All three options represent the same random bytes; encoding changes the text, not the entropy. Base64URL removes padding and avoids the + and / characters, which makes it convenient in configuration files and URL-safe contexts. Use the encoding expected by your JWT library.
A JWT secret is not a finished token
This tool creates key material for an HMAC signing configuration. It does not create a JWT header or payload, sign a token, validate claims, choose expiration rules, or manage rotation. Those decisions belong in the application and its authentication design.
Storage and rotation
Keep the secret outside the repository, restrict who and what can read it, and plan a rotation process. Replacing a live secret immediately invalidates tokens signed only with the previous value unless the application supports an overlap period or multiple verification keys.
Sources and technical basis
The algorithm sizes follow RFC 7518 section 3.2. Random bytes come from the browser’s Web Crypto getRandomValues API. This page generates symmetric HMAC secrets only; it does not generate RSA or elliptic-curve keypairs.
Related developer tools
Random key generator creates generic 128-, 192-, or 256-bit material. Random string generator creates customizable test strings and identifiers. Use the JWT tool when the consuming JWT algorithm determines the required HMAC key size.