Encoding & Crypto Tools

Encode, decode, hash, sign-inspect and generate — using your browser's native crypto engine. Nothing is ever uploaded.

Crypto-grade privacy

Hashing and encryption on this site use the browser's built-in Web Crypto API — the same primitives trusted for TLS. Your input never leaves the device: there is no server to send it to. This makes the tools safe for tokens, keys, password hashes and other sensitive material.

FAQ

Can you recover a password from a hash?

No — and no legitimate tool can. Hashing is one-way. Use the Hash Generator to verify hashes, not to crack them.

Does the JWT decoder verify signatures?

No, it decodes and displays header, payload and expiry. Signature verification requires the secret or public key and is planned as a separate tool.

Which algorithms are used for AES?

AES-256-GCM with a PBKDF2-SHA256 key derived from your password (150,000 iterations, random salt and IV per message).