Is my secret sent anywhere?
No. Tokens are signed with your browser's Web Crypto API. The secret is kept only in the page's memory — it is never saved to storage, never included in a link, and not sent to a server. The page has no share button for that reason.
Why does my API say the signature is invalid?
The most common cause is secret encoding: many frameworks treat the configured secret as Base64, others as plain text. The same characters give different key bytes, so the signature differs. Switch "Secret is" between Text and Base64 to match your server. Other causes are signing with the wrong algorithm and a secret with trailing whitespace.
How long should an HS256 secret be?
At least 32 bytes (256 bits). RFC 7518 requires an HMAC key at least as long as the hash output, and libraries such as jose and .NET's Microsoft.IdentityModel reject shorter keys. The generator warns when the secret is too short for the chosen algorithm.
Are exp and iat in seconds or milliseconds?
Seconds. JWT uses NumericDate: seconds since 1970-01-01T00:00:00Z. A 13-digit value is almost certainly milliseconds from Date.now(), and the generator warns about it.
Can I create a token with alg: none?
Only after ticking an explicit checkbox, and with a warning. An unsigned token can be forged by anyone, so servers must reject it; it is useful only for testing that yours does.
Does it support RS256 or ES256?
Not yet — this version signs with HMAC (HS256, HS384, HS512). To inspect or verify RS256/ES256 tokens, use the JWT decoder, which verifies RSA and ECDSA signatures against a JWK.