Choosing a JWT signing algorithm
HS256, RS256, PS256 or ES256? The right choice depends on who verifies your tokens, what your ecosystem supports and how you manage keys.
Decision guide
- Does anyone other than the issuer verify the tokens? If no, HS256 with a random 256-bit secret is a good choice. If yes, use an asymmetric algorithm so verifiers can't mint tokens.
- Do you need the broadest compatibility? Choose RS256 — every JWT library and identity provider supports it.
- Do you want small tokens and fast signing? Choose ES256 (P-256). Signatures are 64 bytes versus 256 bytes for RS256 with a 2048-bit key.
- Do you want modern RSA padding? PS256 uses RSA-PSS with the same RSA keys; support is widespread but not universal.
Whatever you choose, configure verifiers to accept only that algorithm.
All supported algorithms
| alg | Description | Signing key |
|---|---|---|
| HS256 | HMAC using SHA-256 | Secret ≥ 256 bits |
| HS384 | HMAC using SHA-384 | Secret ≥ 384 bits |
| HS512 | HMAC using SHA-512 | Secret ≥ 512 bits |
| RS256 | RSA signature (PKCS#1 v1.5) using SHA-256 | RSA private key ≥ 2048 bits |
| RS384 | RSA signature (PKCS#1 v1.5) using SHA-384 | RSA private key ≥ 2048 bits |
| RS512 | RSA signature (PKCS#1 v1.5) using SHA-512 | RSA private key ≥ 2048 bits |
| PS256 | RSA-PSS signature using SHA-256 and MGF1 | RSA private key ≥ 2048 bits |
| PS384 | RSA-PSS signature using SHA-384 and MGF1 | RSA private key ≥ 2048 bits |
| PS512 | RSA-PSS signature using SHA-512 and MGF1 | RSA private key ≥ 2048 bits |
| ES256 | ECDSA using P-256 and SHA-256 | EC private key, P-256 |
| ES384 | ECDSA using P-384 and SHA-384 | EC private key, P-384 |
| ES512 | ECDSA using P-521 and SHA-512 | EC private key, P-521 |
Key and signature sizes
HMAC signatures are 32, 48 or 64 bytes. RSA signatures equal the modulus size (256 bytes at 2048 bits, 512 bytes at 4096 bits). ECDSA signatures are 64, 96 or 132 bytes for ES256, ES384 and ES512. Signature size adds directly to the token length that travels with each request.
Create a secret or key pair for any of these algorithms, with PEM, JWK and JWKS export.
Generate keys