Security Tools
Cryptographic utilities are the one category where a browser tool has a clear advantage over a hosted one: a password or a plaintext that is generated or processed on your own device has not been transmitted to anyone, and cannot be logged by a service you do not control.
These tools use the browser's own Web Crypto implementation for random generation, HMAC and encryption. Where an algorithm is offered that is no longer suitable for security work — MD5 and SHA-1, for instance — the interface says so rather than leaving you to find out.
Tools in Security Tools
How these tools behave
- Random values come from the browser's cryptographic random number generator, not from Math.random.
- The JWT tool can verify HMAC-signed tokens against a secret you supply; RSA and ECDSA tokens cannot be verified with a shared secret.
- Nothing you generate here is stored. Refreshing the page loses it.
Frequently asked questions
Are generated passwords ever sent anywhere?
No. They are produced in the page by the browser's random number generator and exist only in the tab until you copy them or close it.
Can I use a hash to store passwords?
Not one of these. A plain hash, even SHA-256, is far too fast for password storage. Password storage needs a deliberately slow function such as bcrypt, scrypt or Argon2.
Guides
- Password strength, measured properly — Why length beats complexity rules, how entropy is calculated, and what a generated password protects you from.
- Hashing, HMAC and encryption are three different things — What each one is for, which of them you can reverse, and why MD5 still has a legitimate use.