◇ 7 tools

Inspect tokens and create cryptographic values

JWT Decoder helps inspect claims and optionally verify HMAC signatures. JWT Generator makes signed test tokens, while Certificate Decoder explains certificate fields without contacting the issuer.

Hash Generator computes digests, HMAC Generator uses a secret key, and Bcrypt Generator creates password hashes. Password Generator offers passwords, passphrases and API keys. These tools solve different tasks: a digest is not a password hash, and decoding a JWT is not signature verification.

Use the right primitive

Use bcrypt for password storage examples, HMAC to authenticate a message with a shared secret, and hashes for checksums or digests. Review the algorithm and parameters required by your own system.

Protect secrets during sharing

These computations happen in the browser, but a copied result, screenshot or optional share link can disclose content. Do not put live credentials into a share link; inspect the destination before copying.

FAQ

Short answers for the things developers usually ask before trusting a tool.

Does decoding a JWT prove it is valid?

No. A JWT payload is readable without verification. Check its signature, expiry, issuer and audience in the system that relies on it.

Is a SHA-256 hash suitable for storing passwords?

A general-purpose hash is too fast for password storage. Use a password hashing scheme such as bcrypt with an appropriate work factor.