Security Tools

37 tools

Five tools that generate or inspect secrets without ever sending one. Everything is computed in the page using the browser's own cryptographic functions. Nothing is stored, which also means nothing can be recovered, so save what you generate before you close the tab.

Free to use with no account. JSON, passwords, hashes, 2FA and text tools run entirely in your browser.

5 tools

About

Five tools that generate or inspect secrets without ever sending one. Everything is computed in the page using the browser's own cryptographic functions. Nothing is stored, which also means nothing can be recovered, so save what you generate before you close the tab.

Which tool answers which question

A new credential comes from the password generator. A token or a test fixture comes from the random string generator, which uses a different alphabet for a reason. An existing password goes into the strength estimate. Verifying that a file or a string matches a published value is the hash tool. Getting into an account with two factor enabled is the code generator.

Local does not mean invulnerable

Computing in the browser removes the network from the threat model and leaves everything else in it. The machine can be shared, the screen can be visible, the clipboard is readable by other software, and a browser extension sees what the page sees. On a computer you do not control, treat every one of these as if the value were being typed in public.

Nothing here remembers anything

There is no account, no history and no recovery. A generated password exists until you navigate away, and a 2FA secret is gone when the tab closes. That is the correct design for a tool handling secrets, and it puts one obligation on you: move the value into your own password manager or authenticator before you leave, because nothing here can produce it again.

FAQ

Do the secrets I enter get transmitted?

No. Generation, strength estimation, hashing and code generation all happen in your browser, and no request carries what you typed.

Does a strong rating mean the password is safe?

It means the string is structurally strong. Reuse across sites and appearance in a past breach are both invisible to any structural score, and both matter more.

Can I keep my 2FA secrets here?

No, and you should not want to. There is no vault, no sync and no backup. Use it as a fallback when your authenticator is out of reach.

Related tools

Generate strong passwords and tokens, estimate password strength, compute SHA digests and produce TOTP codes. Everything is calculated in your browser.

Security Tools - Passwords, Hashes and 2FA Codes