// 11 tools · 0 uploads · no sign-up

Tools

Everyday utilities for security and infrastructure work. They run entirely in your browser, and each page is locked by your browser so it cannot open a connection to send what you paste — to anyone, including us.

Recognised in your browser. The text is passed to the tool through this tab’s session storage — never the address bar — and deleted as soon as the tool opens.

Certificate & CSR Decoder

Read certificates, CSRs, .p7b bundles and CRLs — then check the chain reaches a trusted root, covers your host name, follows the CA/Browser Forum rules, and isn’t revoked.

PEMDERCSR.p7bCRLLint
Open →

JWT Inspector

Decode a JSON Web Token, verify its signature, and check it the way your API should — plus inspect a JWKS or OpenID Connect configuration for risky settings.

HSRSPSESEdDSAJWKS
Open →

SAML Inspector

Decode a SAMLResponse or AuthnRequest and see who it logs in, for which service and until when — with checks for unsigned assertions, signature wrapping and comment tricks.

SAMLResponseAuthnRequestRedirectXSW checksSSO
Open →

Encode / Decode Workbench

Base64, hex, URL, HTML, Unicode, Base32, quoted-printable, MIME headers, PowerShell -EncodedCommand, gzip/deflate (SAML), punycode, ROT and XOR — auto-detected, chainable and shareable as a link.

Base64PowerShell -encSAMLPunycodeBase32K8s Secret
Open →

Security Headers & CSP Analyzer

Paste a site’s response headers or its Content-Security-Policy and see what is missing, what is misconfigured and how to fix it — HSTS, CSP, framing, cookies, CORS and more.

CSPHSTSCookiesCORSX-Frame-Optionsnginx / Apache
Open →

IOC Extractor & Defanger

Pull URLs, domains, IP addresses, email addresses, hashes and CVE IDs out of any text — defanged and ready for a ticket — and brute-force single-byte XOR.

IOCDefanghxxpIPv4 / IPv6SHA-256XOR
Open →

Hash & Checksum Verifier

Check downloads against their published checksum — and verify the checksum file’s own OpenPGP or minisign signature, so you know who published it.

SHA-256SHA256SUMSOpenPGPminisignHMAC
Open →

Timestamp Converter

Read any timestamp — Unix, Active Directory / FILETIME, .NET ticks, Chrome, Apple, Excel — or the time inside a UUID, ULID or ObjectId, across time zones.

UnixAD FILETIME.NET ticksUUID v7ULIDTime zones
Open →

Cron Explainer

Read a schedule in plain English and see its next runs — Linux cron, Kubernetes, GitHub Actions, Quartz/Spring, AWS EventBridge and systemd timers.

crontabQuartzEventBridgesystemdKubernetes
Open →

OpenSSL Command Builder

Pick a task and your platform, get the exact command to run on your own machine — then paste the output back to have it explained. Keys never touch a website.

CSRPFXKey matchs_clientOutput explained
Open →

Secret Generator

Passwords, passphrases, API keys, encryption keys and UUIDs from your browser’s cryptographic random generator — with the strength in bits.

PasswordPassphraseAPI keyAESTOTPUUID v7
Open →

How the lock works — and where it stops

A rule your own browser enforces, which you can check in under a minute — plus the limits we think you should know about.

1 · blocked

No background connections

Tool pages are served with connect-src 'none': your browser refuses every fetch, XHR, WebSocket and beacon. Nothing loads from other sites, and scripts run only from this site’s own files or as inline code pinned by SHA-256 hash.

2 · not stored

No storage, no analytics

Inputs live only in the open tab and are gone when you close it. No cookies, analytics or accounts. The only things remembered are your light/dark theme and, in the current tab only, the “wipe when I leave” setting.

3 · verifiable

Check it yourself

Watch the Network tab while you use a tool, go offline and keep working, or press Test the lock on any tool page to see a request get refused.

Where the lock stops

  • Browser extensions that can access this site can read anything on the page. For sensitive data, use a private window with extensions turned off.
  • A browser policy cannot stop a page’s own code from navigating away or requesting one of this site’s own files. That part rests on the code: it never puts your input into a link or a request, and each tool shows its version and build.
  • Your clipboard keeps whatever you copy. Copy buttons for sensitive output clear it again after 30 seconds.
  • Writing assistants (Grammarly, LanguageTool, cloud spell-check) send typed text to their servers; every input here tells them to stay out.

The policy on every tool page

default-src 'none';
script-src 'self' 'sha256-<hash of each inline script>';
style-src 'self' 'unsafe-inline';
img-src 'self' data:;
font-src 'self';
manifest-src 'self';
connect-src 'none';
form-action 'none';
worker-src 'none';
frame-src 'none';
media-src 'none';
object-src 'none';
frame-ancestors 'none';
base-uri 'none';
require-trusted-types-for 'script';
trusted-types 'none'

Compare with what the server really sends: curl -sI https://blog.anlabs.net/tools/jwt-inspector/ | grep -i content-security-policy