Cryptographically sign and verify HS256 JSON Web Tokens in your browser with 100% client privacy.
Execution runs 100% locally inside the browser sandbox using HTML5 Canvas, Web Cryptography Subtle API, and Web Workers. Zero egress.
Zero network latency. Operates completely offline with zero dependencies on third-party backend servers or cloud services.
Built according to official RFC specifications, cryptographic test vectors, and enterprise-grade data transformation standards.
Input your HMAC shared secret key (e.g. your JWT secret).
Customize claims (sub, name, role, exp) in formatted JSON.
Copy the signed JWT string or paste an existing token to verify signature integrity.
All cryptographic operations execute locally using window.crypto.subtle with zero server transmission or external API requests.
HMAC with SHA-256 (HS256), the most widely adopted standard for symmetric JSON Web Token signing.
Zero-egress companion tools in the Security & Network suite
Audit CSP, HSTS, X-Frame-Options, and security headers with OWASP grading (A+ to F).
Measure cryptographic randomness, Shannon entropy (0-8 bits/byte), Chi-square test, and byte distributions.
Generate secure RFC 6238 Base32 TOTP secret keys and standard otpauth:// URIs for Google Authenticator.
Construct and validate HTTP CSP headers and meta tags.