The Risk of Pasting JWT Secrets Online
JWT (RFC 7519) authentication relies on HMAC secret keys or private keys. Entering production secrets into third-party web debuggers exposes your backend to credential theft and unauthorized token forging. Lucentool computes HMAC signatures entirely offline.
HS256 HMAC-SHA256 Architecture
- Data Concatenation:
Base64Url(Header) + "." + Base64Url(Payload) - HMAC Signature: Calculated using the SHA-256 hash algorithm and your secret key over the concatenated payload.
- Base64URL Encoding: Strips trailing padding
=, replaces+with-, and/with_, ensuring safe transmission across HTTP headers and URL query strings.