Skip to main content

Security 5

Hashing, JWT decoding, password generation and CORS

Inspecting a token, hashing a file, or generating a credential are all things you should be able to do without handing the material to a third party. These tools keep that work on your own machine.

// Tools in this category

// Why a browser tool is the safe option here

Security work involves exactly the values you must not paste into an unknown web service: access tokens, session identifiers, API keys, password candidates. The common online decoders and hash generators send that input to a server, where it may be logged. Every tool in this category runs as client-side JavaScript, so the value you paste is processed in the tab you are looking at and disappears when you close it.

// Decoding is not verification

A recurring mistake is to treat a decoded JWT payload as trustworthy. Decoding only reverses Base64URL; it proves nothing about who issued the token. Verification needs the shared secret or the issuer public key and belongs on the server, in a maintained library. Use the decoder to see what is inside a token while you debug, and keep the signature check where it can actually be enforced.

// What to reach for

The JWT Decoder shows the header, payload and expiry of a token so you can confirm which claims your identity provider is issuing. The Hash Generator produces SHA-1 through SHA-512 digests at once. The Password Generator uses the browser cryptographic random source and reports the entropy you are actually getting. The CORS Header Generator builds the Access-Control headers and refuses the combinations browsers reject.

// Security: frequently asked questions

Is it safe to paste a production token into these tools?
Yes. The decoding runs in your browser and the token is never sent anywhere, stored or logged. That said, treat any token you have pasted into a shared screen or a recorded session as exposed, and rotate it if in doubt.
Can I verify a signature here?
No. Verification requires the HMAC secret or the issuer public key, and a browser page is the wrong place to handle either. Verify on the server with a library such as jose, jsonwebtoken or PyJWT.

// Other categories