Generate a JWT Secret in 5 Minutes
Go from zero to a working HS256 signing secret quickly. Use the free JWT Secret Generator for at least 256 bits of entropy, store the value outside source control, sign a short-lived test token in your stack, and verify it before you ship anything to staging or production.
Last updated August 26, 2026
Steps
- 1
Open the JWT Secret Generator and click Generate with the default 256-bit setting.
- 2
Copy the hex key and set it as JWT_SECRET in your environment — never commit it to git.
- 3
Sign a test token with your JWT library using algorithm HS256 and a short expiresIn (for example 15–60 minutes).
- 4
Paste the token and secret into the JWT Validator to confirm the signature and claims.
- 5
Read the JWT Best Practices Checklist and the store-secrets guide before deploying.
Frequently Asked Questions
What bit length should I use?
Use at least 256 bits (32 bytes) for HS256 in production. 128 bits is only acceptable for throwaway local experiments — never for staging or production.
Is browser generation safe?
Yes. Keys are created with crypto.getRandomValues() (Web Crypto) in your browser. Nothing is uploaded. Still treat the copied secret as confidential afterward.
Can I reuse one secret across environments?
No. Generate separate secrets for development, staging, and production so a leak in one environment cannot forge tokens in another.
Hex or Base64 for storage?
Either works if your library uses the same encoding on sign and verify. Hex is common in .env files; keep the exact string identical on every service that verifies.
Continue
Related tools and reading on JWTSecrets.