JWT HMAC Secret Generator

Generate strong shared secrets for HS256, HS384, and HS512 locally.

100% Local Processing

About the JWT HMAC Secret Generator

A JWT HMAC secret is shared key material used by symmetric JSON Web Token algorithms such as HS256, HS384, and HS512. This tool creates cryptographically secure random bytes in your browser, then displays the same bytes as Base64URL, Base64, or hexadecimal text. It does not upload or store the generated value. HMAC secrets are different from SHA hashes: SHA-256 is a hash function, while HS256 combines HMAC, SHA-256, and a secret key. Asymmetric JWT algorithms such as RS256, ES256, and EdDSA use private/public key pairs instead and are outside this tool.

How to generate a JWT HMAC secret

  1. Choose the HS256, HS384, or HS512 preset required by your JWT configuration.
  2. Choose Base64URL, Base64, or hexadecimal output. Changing format re-encodes the same random bytes.
  3. Copy the displayed value and immediately place it in protected secret storage.
  4. Configure the signing and verification sides to use the same secret and algorithm.
  5. Remove the value from any temporary clipboard history or unprotected notes when you are finished.

Examples and worked results

HS256 secret material

Input
HS256 preset · 32 random bytes · Base64URL
Result
dGhpcy1pcy1hLWZpeGVkLWZha2UtZXhhbXBsZS1vbmx5

This fixed string illustrates the output shape only. Generate a fresh value for real configuration.

Random bytes first, encoding second

The browser allocates a byte array and fills it with crypto.getRandomValues(). The presets create 32 bytes for HS256, 48 bytes for HS384, or 64 bytes for HS512. These are straightforward strong lengths aligned with the output size of the corresponding SHA family; they are presets, not a claim that no other key length is allowed.

Base64URL, Base64, and hexadecimal output are encodings of that same byte array. Switching formats does not regenerate, truncate, pad, or increase the entropy of the secret. Selecting a different algorithm or pressing Regenerate creates a completely new byte array.

HMAC algorithms use one shared secret for signing and verification. RSA, ECDSA, and EdDSA algorithms use asymmetric key pairs, which this generator does not create.

Common use cases

  • Setting up JWT HMAC signing for a new application
  • Rotating an existing HMAC JWT secret
  • Creating separate local-development and staging secrets
  • Preparing secret material for deployment-platform or secret-manager storage

Important notes and limitations

  • This tool supports shared-secret material for HS256, HS384, and HS512 only.
  • It does not generate RSA, ECDSA, or EdDSA key pairs, sign tokens, verify tokens, or manage keys.
  • The secret is discarded on refresh and is not stored by VoltUtils; you are responsible for secure storage, access control, backup, and rotation.
  • Strong generated bytes cannot compensate for insecure application architecture, weak claim validation, secret exposure, or an unsafe JWT implementation.

Practical tips

  • Use a separate secret for each application and environment.
  • Rotate secrets according to your operational and incident-response needs.
  • Do not send secrets through chat or email and never commit them to Git.
  • Prefer protected secret storage provided by your deployment environment or a dedicated secret manager.
  • A configuration placeholder can look like JWT_SECRET=<generated-secret>; do not put the real value in documentation or a URL.

Frequently Asked Questions

What is a JWT secret?

It is shared key material used by HMAC JWT algorithms to create and verify message authentication codes. Both sides that sign and verify need protected access to the same secret.

Which JWT algorithms use a shared secret?

HS256, HS384, and HS512 are HMAC algorithms that use a shared secret. Not every JWT algorithm uses one.

Does RS256 use this secret?

No. RS256 is asymmetric: signing uses a private key and verification uses the corresponding public key.

How long should an HS256 secret be?

This HS256 preset generates 32 random bytes, or 256 bits. Strong random key material is important, but secure use also depends on storage, access control, rotation, and correct JWT validation.

Is Base64URL stronger than hex?

No. Base64URL, Base64, and hex are different text representations of the same random bytes, so changing the encoding does not change the entropy.

Does VoltUtils store my generated secret?

No. Generation and encoding happen locally in the browser. The secret is not placed in local storage, cookies, the URL, or an analytics event.

Can I use the generated secret in production?

The generator produces cryptographically random bytes suitable as HMAC secret material. Safe production use also requires protected storage, limited access, planned rotation, and a correctly configured JWT library.

Should I commit the secret to Git?

No. Put it in deployment-platform secret storage, a secret manager, or a protected environment variable managed outside source control.

Is this a password generator?

No. It generates raw random secret material for machine configuration rather than a password intended for a person to remember or enter.

Is HS256 the same as SHA-256 hashing?

No. SHA-256 is a hash function. HS256 uses HMAC with SHA-256 and a shared secret key to authenticate JWT content.