Developer, security and utility tools that help us work smarter every day.


25 tools
Pull readable text out of any binary and measure its entropy, to see what a file references and whether it is packed or encrypted.
Open toolList what an archive contains and flag traversal paths, disguised executables, encrypted entries and extreme compression ratios before extracting it.
Open toolGenerate and check time-based 2FA codes from a base32 secret, with a live countdown and clock-drift detection.
Open toolPeel stacked HTML entity, percent, hex, escape, fromCharCode and Base64 layers off a payload without executing it.
Open toolInspect an image for signs of editing with error level analysis, edge mapping, least-significant-bit and channel views.
Open toolBuild and sign a JSON Web Token with HS256, HS384 or HS512, using your own claims and secret.
Open toolIdentify an unknown timestamp by decoding it as Windows FILETIME, Chrome WebKit, Apple Cocoa, HFS+, OLE, FAT and six more encodings at once.
Open toolScan code, config or logs for leaked API keys, tokens, private keys and database passwords before you commit or share them.
Open toolCheck how crackable a password really is, based on known patterns and dictionaries, not just character-type rules.
Open toolBreak down text by letter frequency, a classic first step in cracking a substitution cipher.
Open toolEncode or decode text with a Caesar shift cipher, or crack one with an unknown shift using letter-frequency analysis.
Open toolHide a short text message inside a PNG’s pixel data, or reveal one that’s already hidden.
Open toolInspect a JSON Web Key or JWKS document, field by field, without exposing private key material.
Open toolHash a password with bcrypt, or verify a password against an existing bcrypt hash.
Open toolEncrypt or decrypt text with a passphrase using AES-256-GCM.
Open toolScan text for zero-width spaces, bidi overrides, and other invisible characters used to hide or disguise content.
Open toolParse raw email headers and explain the Received chain and SPF/DKIM/DMARC results.
Open toolCheck a file’s name and actual signature for double extensions, disguised executables, and other red flags.
Open toolRead a PEM/DER X.509 certificate’s subject, issuer, validity, and public key details.
Open toolCompute an HMAC-SHA1/256/384/512 of a message with a secret key.
Open toolGuess what algorithm produced a given hash, based on its length and format.
Open toolDecode a JSON Web Token’s header and payload, and verify an HS256 signature with a secret.
Open toolGenerate a cryptographically random password with the character types and length you choose.
Open toolCompute SHA-1, SHA-256, SHA-384, and SHA-512 checksums for any file, to verify it wasn’t altered.
Open toolCompute MD5, SHA-1, SHA-256, SHA-384 and SHA-512 hashes of any text.
Open tool