Skip to content
BEAD

JWT Secret Strength

Check a JWT signing secret for length, entropy, and known weak values.

🔒 Secrets are analysed entirely in your browser.

How strong should a JWT secret be?

RFC 7518 says HMAC keys should be at least as long as the hash output: 32 bytes for HS256, 48 for HS384, 64 for HS512. In practice, treat 32 random bytes as the minimum and 64 as comfortable.

Always generate the secret with a CSPRNG — never use a phrase you could type. Password Generator with 64 chars or UUID v4 are both fine sources.

You might also like