Tools for security analysis and management
Create, decode, and validate JSON Web Tokens (JWT) with an intuitive interface. Includes templates for common token types and security analysis.
Decode JWT tokens to inspect header, payload, and signature.
Analyze password strength, calculate entropy, and estimate crack time. Generate secure passwords with customizable options.
Generate secure passwords with customizable options for length and character types
Decode and inspect SSL certificates to understand their contents, validity, and trust chain.
Analyze HTTP security headers to improve website security posture and compliance.
Hash text or files with MD5 and the SHA family, output hex or Base64, and verify against an expected checksum.
Generate keyed-hash message authentication codes (HMAC) with SHA-1/256/384/512 using the Web Crypto API.
Encrypt and decrypt text with AES-GCM and a password-derived key — all in your browser via Web Crypto.
Generate live time-based one-time passcodes from a Base32 secret, with a countdown and the otpauth URI.
Assemble and validate a CSP directive by directive, with presets and a copyable header and meta tag.
Build WebAuthn options, run local browser ceremonies, and decode challenge, origin, RP ID hash, flags, and counters.
Inspect mail routing, timing, SPF, DKIM, DMARC, ARC, identity alignment, anomalies, and safe redacted exports.