JWT test token generator

One click generates a matched set of tokens for testing an API's authentication: one that must be accepted and nine that must be rejected — expired, not yet valid, wrong audience, wrong issuer, wrong key, tampered, unsigned, algorithm-swapped and missing expiration.

🔒 Keys and tokens are generated in your browser.

Test token set

A fresh key is generated locally each time.

Why negative tests matter

Most JWT vulnerabilities are verifiers that accept tokens they should reject. A happy-path test proves your API works; these cases prove it is safe. Point your API (in a test environment) at the generated secret or JWKS and assert that exactly one token is accepted.

Using the fixture

  1. Generate the set and copy the verification key into your API's test configuration.
  2. Copy all tokens as a JSON fixture and loop over them in your test suite.
  3. Assert a 2xx response for valid and a 401 for every other case.

Time-based tokens are relative to when you generated them; regenerate the set when the valid token expires (1 hour). To build a single token with custom claims, use the JWT encoder. To understand why a token is rejected, paste it into JWTDecoder.com.