Skip to content

Security Tools

Cryptographic utilities are the one category where a browser tool has a clear advantage over a hosted one: a password or a plaintext that is generated or processed on your own device has not been transmitted to anyone, and cannot be logged by a service you do not control.

These tools use the browser's own Web Crypto implementation for random generation, HMAC and encryption. Where an algorithm is offered that is no longer suitable for security work — MD5 and SHA-1, for instance — the interface says so rather than leaving you to find out.

Tools in Security Tools

How these tools behave

  • Random values come from the browser's cryptographic random number generator, not from Math.random.
  • The JWT tool can verify HMAC-signed tokens against a secret you supply; RSA and ECDSA tokens cannot be verified with a shared secret.
  • Nothing you generate here is stored. Refreshing the page loses it.

Frequently asked questions

Are generated passwords ever sent anywhere?

No. They are produced in the page by the browser's random number generator and exist only in the tab until you copy them or close it.

Can I use a hash to store passwords?

Not one of these. A plain hash, even SHA-256, is far too fast for password storage. Password storage needs a deliberately slow function such as bcrypt, scrypt or Argon2.

Guides