Tools
Everyday utilities for security and infrastructure work. They run entirely in your browser, and each page is locked by your browser so it cannot open a connection to send what you paste — to anyone, including us.
Recognised in your browser. The text is passed to the tool through this tab’s session storage — never the address bar — and deleted as soon as the tool opens.
Certificate & CSR Decoder
Read certificates, CSRs, .p7b bundles and CRLs — then check the chain reaches a trusted root, covers your host name, follows the CA/Browser Forum rules, and isn’t revoked.
JWT Inspector
Decode a JSON Web Token, verify its signature, and check it the way your API should — plus inspect a JWKS or OpenID Connect configuration for risky settings.
SAML Inspector
Decode a SAMLResponse or AuthnRequest and see who it logs in, for which service and until when — with checks for unsigned assertions, signature wrapping and comment tricks.
Encode / Decode Workbench
Base64, hex, URL, HTML, Unicode, Base32, quoted-printable, MIME headers, PowerShell -EncodedCommand, gzip/deflate (SAML), punycode, ROT and XOR — auto-detected, chainable and shareable as a link.
Security Headers & CSP Analyzer
Paste a site’s response headers or its Content-Security-Policy and see what is missing, what is misconfigured and how to fix it — HSTS, CSP, framing, cookies, CORS and more.
IOC Extractor & Defanger
Pull URLs, domains, IP addresses, email addresses, hashes and CVE IDs out of any text — defanged and ready for a ticket — and brute-force single-byte XOR.
Hash & Checksum Verifier
Check downloads against their published checksum — and verify the checksum file’s own OpenPGP or minisign signature, so you know who published it.
Timestamp Converter
Read any timestamp — Unix, Active Directory / FILETIME, .NET ticks, Chrome, Apple, Excel — or the time inside a UUID, ULID or ObjectId, across time zones.
Cron Explainer
Read a schedule in plain English and see its next runs — Linux cron, Kubernetes, GitHub Actions, Quartz/Spring, AWS EventBridge and systemd timers.
OpenSSL Command Builder
Pick a task and your platform, get the exact command to run on your own machine — then paste the output back to have it explained. Keys never touch a website.
Secret Generator
Passwords, passphrases, API keys, encryption keys and UUIDs from your browser’s cryptographic random generator — with the strength in bits.
How the lock works — and where it stops
A rule your own browser enforces, which you can check in under a minute — plus the limits we think you should know about.
No background connections
Tool pages are served with connect-src 'none': your browser refuses every fetch, XHR, WebSocket and beacon. Nothing loads from other sites, and scripts run only from this site’s own files or as inline code pinned by SHA-256 hash.
No storage, no analytics
Inputs live only in the open tab and are gone when you close it. No cookies, analytics or accounts. The only things remembered are your light/dark theme and, in the current tab only, the “wipe when I leave” setting.
Check it yourself
Watch the Network tab while you use a tool, go offline and keep working, or press Test the lock on any tool page to see a request get refused.
Where the lock stops
- Browser extensions that can access this site can read anything on the page. For sensitive data, use a private window with extensions turned off.
- A browser policy cannot stop a page’s own code from navigating away or requesting one of this site’s own files. That part rests on the code: it never puts your input into a link or a request, and each tool shows its version and build.
- Your clipboard keeps whatever you copy. Copy buttons for sensitive output clear it again after 30 seconds.
- Writing assistants (Grammarly, LanguageTool, cloud spell-check) send typed text to their servers; every input here tells them to stay out.
The policy on every tool page
default-src 'none'; script-src 'self' 'sha256-<hash of each inline script>'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; font-src 'self'; manifest-src 'self'; connect-src 'none'; form-action 'none'; worker-src 'none'; frame-src 'none'; media-src 'none'; object-src 'none'; frame-ancestors 'none'; base-uri 'none'; require-trusted-types-for 'script'; trusted-types 'none'
Compare with what the server really sends: curl -sI https://blog.anlabs.net/tools/jwt-inspector/ | grep -i content-security-policy