Security 5
Hashing, JWT decoding, password generation and CORS
Inspecting a token, hashing a file, or generating a credential are all things you should be able to do without handing the material to a third party. These tools keep that work on your own machine.
// Tools in this category
Hash Generator
Generate SHA-1, SHA-256, SHA-384 and SHA-512 hashes from text, all at once, in your browser. Uses the Web Crypto API, and nothing you type is uploaded.
JWT Decoder
Decode JSON Web Tokens instantly: view header, payload and signature, turn exp/iat/nbf into dates and spot expired tokens. Runs entirely in your browser.
Password Generator
Generate strong random passwords in your browser using crypto.getRandomValues. Choose length, character sets and how many to produce, with an entropy readout.
CORS Header Generator
Build the Access-Control response headers for your API from a form: allowed origin, methods, headers, exposed headers, credentials and max-age.
CSP Generator
Build a Content-Security-Policy from a form, with warnings for settings that defeat it. Outputs the header, a Report-Only version, a meta tag and NGINX config.
// Why a browser tool is the safe option here
Security work involves exactly the values you must not paste into an unknown web service: access tokens, session identifiers, API keys, password candidates. The common online decoders and hash generators send that input to a server, where it may be logged. Every tool in this category runs as client-side JavaScript, so the value you paste is processed in the tab you are looking at and disappears when you close it.
// Decoding is not verification
A recurring mistake is to treat a decoded JWT payload as trustworthy. Decoding only reverses Base64URL; it proves nothing about who issued the token. Verification needs the shared secret or the issuer public key and belongs on the server, in a maintained library. Use the decoder to see what is inside a token while you debug, and keep the signature check where it can actually be enforced.
// What to reach for
The JWT Decoder shows the header, payload and expiry of a token so you can confirm which claims your identity provider is issuing. The Hash Generator produces SHA-1 through SHA-512 digests at once. The Password Generator uses the browser cryptographic random source and reports the entropy you are actually getting. The CORS Header Generator builds the Access-Control headers and refuses the combinations browsers reject.
// Security: frequently asked questions
- Is it safe to paste a production token into these tools?
- Yes. The decoding runs in your browser and the token is never sent anywhere, stored or logged. That said, treat any token you have pasted into a shared screen or a recorded session as exposed, and rotate it if in doubt.
- Can I verify a signature here?
- No. Verification requires the HMAC secret or the issuer public key, and a browser page is the wrong place to handle either. Verify on the server with a library such as jose, jsonwebtoken or PyJWT.
// Other categories
Looking for something that is not here yet? The Japanese edition of this category lists 5 tools. The tools themselves work the same way regardless of the language of the surrounding page.