Which key do I need?
- HS256/384/512 — a random secret at least as long as the hash (256/384/512 bits). Share it only with services that verify tokens.
- RS256/PS256 — an RSA key pair, 2048 bits minimum (3072 bits for long-lived keys). Publish the public key as a JWKS.
- ES256/384/512 — an EC key pair on P-256, P-384 or P-521 respectively. Much smaller keys and signatures than RSA.
Key IDs
Each generated key gets a kid equal to its RFC 7638 JWK thumbprint — a SHA-256 hash of the key's required public members. It is stable, unique and verifiable, which makes key rotation straightforward: add the new key to your JWKS, start signing with its kid, and remove the old key once its tokens have expired.
Handling private keys
Keys generated here exist only in this browser tab until you copy or download them. For production, generate keys inside your key management system (KMS, HSM or secrets manager) so the private key never exists outside it. Use this page for development, testing and learning.
Next: sign a token with your new key or read how to sign a JWT.