Security tools that never send your data anywhere
Generate a strong password, hash a file checksum, inspect a JWT, produce random identifiers — all computed locally, so the sensitive part never leaves your machine.
A security tool that uploads your input is not a security tool
This is the category where the usual arrangement makes least sense. A password generated on someone else’s server has, by definition, existed on someone else’s server. A token pasted into a decoder has been logged by whatever was behind that form. Every tool here runs entirely in your browser as client-side JavaScript, which you can confirm the same way you would confirm it anywhere: open the network tab and watch nothing get sent. You can load the page, disconnect from the network, and it still works.
Randomness that is actually random
The password generator and the UUID generator both draw from the browser’s Web Crypto API — crypto.getRandomValues — not from Math.random, which is fast and predictable and unsuitable for anything anyone might try to guess. You choose length and character classes; longer beats clever, and a long generated passphrase stored in a password manager is worth more than a short one you can remember.
Hashing, encoding, and the difference between them
These get confused constantly, and the confusion causes real vulnerabilities. Hashing is one-way and is what you use to verify that a downloaded file matches its published SHA-256 checksum. Base64 is encoding, not encryption — it is trivially reversible, which is exactly why the Base64 converter can decode anything you give it, and why nothing secret should ever be “protected” by it. A JWT is signed, not encrypted: its payload is Base64url and anyone holding the token can read it, which is what the JWT decoder shows you. Treat what you see there as public.
Looking for something else? Browse all Toolz tools.