๐ ๏ธ Developer Tools
JSON formatter, URL encoder, hash generator and more
Beautify, validate and format JSON. Free JSON beautifier, validator, and pretty printer.
Open tool โEncode or decode URL strings. Free URL encoder and decoder tool.
Open tool โGenerate SHA-1, SHA-256, SHA-512, and MD5 hashes online.
Open tool โGenerate strong, secure, random passwords on demand.
Open tool โTest and debug regular expressions with real-time matching and capture groups.
Open tool โGenerate random UUID v4 identifiers. Bulk generate up to 100 UUIDs.
Open tool โConvert Unix timestamps to dates and back. Epoch converter with timezone support.
Open tool โBuild and explain cron schedule expressions visually. See next execution times.
Open tool โMinify HTML, CSS, and JavaScript. See size savings instantly.
Open tool โCalculate CIDR notation, network address, broadcast, and host ranges.
Open tool โCreate beautiful CSS gradients with a visual editor. Copy CSS code.
Open tool โCreate CSS box shadows visually with live preview. Copy CSS code.
Open tool โConvert between binary, decimal, octal and hexadecimal.
Open tool โConvert between bytes, KB, MB, GB, TB and more data sizes.
Open tool โDecode and inspect JSON Web Tokens. View header, payload and signature.
Open tool โCompare two texts side by side and see the differences highlighted.
Open tool โThe utilities you reach for a dozen times a day and never want to think about โ formatting a blob of JSON, decoding a token to see why auth is failing, generating a UUID, working out what a cron expression actually means.
All of them run in your browser. That is the point: pasting a production JWT, an internal API response or a customer record into a random web form is a habit worth breaking, and here there is no server to send it to. Open the network tab and check.
Which tool do I want?
| If youโฆ | Use |
|---|---|
| You have unreadable JSON and want it formatted or validated | JSON Formatter |
| Auth is failing and you need to see what is in the token | JWT Decoder |
| You are writing a pattern and want to test it live | Regex Tester |
| You need a strong password or an API key | Password Generator |
| A cron line is opaque and you want it in English | Cron Expression Generator |
| You are planning subnets or checking whether an IP is in range | Subnet Calculator |
| You have a Unix timestamp and need a date | Timestamp Converter |
| You want to see exactly what changed between two files | Text Compare / Diff |
Decoding a JWT is not verifying it
The JWT decoder here shows you the header and payload, because both are plain base64url โ anyone holding the token can read them. What it does not do is check the signature, and that distinction has caused real security incidents.
A decoded token showing admin: true tells you what the token claims, not whether that claim is true. Verification means recomputing the signature with the issuer's key and confirming it matches, then checking the expiry, the issuer and the audience. That has to happen on your server, with a library, every time.
So: never put secrets in a JWT payload, since it is readable by design. And never trust a claim you have only decoded. The decoder is a debugging aid for working out why auth is behaving oddly โ it is not an authorisation check.