🛠️ Developer Tools
JSON-muotoilija, URL-koodari, hash-generaattori ja paljon muuta
Kaunista, tarkista ja muotoile JSON. Ilmainen JSON-kaunistaja, validaattori ja tulostin.
Avaa työkalu →Koodaa tai purkaa URL-merkkijonot. Ilmainen URL-kooderin ja dekooderin työkalu.
Avaa työkalu →Luo SHA-1, SHA-256, SHA-512 ja MD5 hash-arvot verkossa.
Avaa työkalu →Luo vahvoja, turvallisia, satunnaisia salasanoja pyynnöstä.
Avaa työkalu →Testaa ja virheenkorjaa säännöllisiä lausekkeita reaaliaikaisella vastaavuudella ja sieppausryhmillä.
Avaa työkalu →Luo satunnaisia UUID v4 -tunnisteita. Luo jopa 100 UUID:tä joukossa.
Avaa työkalu →Muunna Unix-aikaleimoja päivämääriksi ja takaisin. Epookin muunnin aikavyöhykkeen tuella.
Avaa työkalu →Rakenna ja selitä cron-aikakaavien lausekkeita visuaalisesti. Katso seuraavat suoritusajat.
Avaa työkalu →Pienennä HTML, CSS ja JavaScript. Näe koon säästöt välittömästi.
Avaa työkalu →Laske CIDR-merkintä, verkon osoite, broadcast ja isäntäalueet.
Avaa työkalu →Luo kauniita CSS-liukuvärejä visuaalisella editorilla. Kopioi CSS-koodi.
Avaa työkalu →Luo CSS box shadow -varjoja visuaalisesti live-esikatselulla. Kopioi koodi.
Avaa työkalu →Muunna binääri-, desimaali-, oktaali- ja heksadesimaalilukujen välillä.
Avaa työkalu →Muunna tavujen, KB, MB, GB, TB ja muiden datakokojen välillä.
Avaa työkalu →Dekoodaa ja tarkasta JSON Web Tokeneja. Näytä header, payload ja allekirjoitus.
Avaa työkalu →Vertaa kahta tekstiä vierekkäin ja näe erot korostettuna.
Avaa työkalu →The utilities you reach for a dozen times a day and never want to think about — formatting a blob of JSON, decoding a token to see why auth is failing, generating a UUID, working out what a cron expression actually means.
All of them run in your browser. That is the point: pasting a production JWT, an internal API response or a customer record into a random web form is a habit worth breaking, and here there is no server to send it to. Open the network tab and check.
Which tool do I want?
| If you… | Use |
|---|---|
| You have unreadable JSON and want it formatted or validated | JSON-muotoilija |
| Auth is failing and you need to see what is in the token | JWT-dekooderi |
| You are writing a pattern and want to test it live | Regex-testaaja |
| You need a strong password or an API key | Salasanageneraattori |
| A cron line is opaque and you want it in English | Cron-lausekkeen generaattori |
| You are planning subnets or checking whether an IP is in range | Aliverkkolaskuri |
| You have a Unix timestamp and need a date | Aikaleiman muunnin |
| You want to see exactly what changed between two files | Tekstien vertailu / Diff |
Decoding a JWT is not verifying it
The JWT decoder here shows you the header and payload, because both are plain base64url — anyone holding the token can read them. What it does not do is check the signature, and that distinction has caused real security incidents.
A decoded token showing admin: true tells you what the token claims, not whether that claim is true. Verification means recomputing the signature with the issuer's key and confirming it matches, then checking the expiry, the issuer and the audience. That has to happen on your server, with a library, every time.
So: never put secrets in a JWT payload, since it is readable by design. And never trust a claim you have only decoded. The decoder is a debugging aid for working out why auth is behaving oddly — it is not an authorisation check.