Security
Hashes, passwords and encoding for everyday security work.
9 tools
Build a CSP directive by directive, with the two mistakes that make a policy useless flagged as you make them.
Generate MD5, SHA-1, SHA-256, SHA-384 and SHA-512 hashes, or verify a checksum.
What kind of hash is this? A ranked shortlist, and an honest note about when the answer cannot be known.
Sign a message with a secret key, or check a webhook signature you were sent.
Read the header, claims and expiry of a JSON Web Token — without sending it anywhere.
Sign a test token, or check whether one was really signed with your secret.
Measure how many guesses a password would actually take — not whether it has a capital letter.
Encrypt a note with a password, in your browser — AES-GCM with a properly derived key, not a toy cipher.
Check that the two-factor secret you saved really produces the code on your phone — before the phone is gone.