Debug web protocols and API flows with JWT, hashing, headers, HTTP, OpenAPI, and request builders.
32 tools
Paste an OpenAPI/Swagger JSON spec to visualize your API endpoints.
Decode JSON Web Tokens instantly. Never sends your token to any server.
Encode, decode, and verify JWT tokens in one local-first workspace.
Instantly generate MD5, SHA-1, SHA-256, and SHA-512 hashes from text.
Generate an MD5 hash quickly with a focused single-algorithm workflow.
Test and evaluate regular expressions in real-time natively in your browser.
Generate practical regex patterns for common validation and parsing tasks.
Build, parse, and understand cron schedules easily.
Decode raw User-Agent strings to identify browser, engine, OS, CPU, and device details.
Visualize the next execution times for any cron expression.
Searchable reference for all HTTP status codes with descriptions.
Interactive Unix file permission calculator. Toggle permissions or enter octal directly.
Calculate network, broadcast, host ranges, and masks from IPv4 CIDR blocks.
Parse URLs into components and interactively edit query parameters.
Decode PEM-encoded X.509 certificates and inspect all details locally.
Build HTTP requests visually and generate cURL, JavaScript fetch, or Python code.
Convert cURL commands to JavaScript, Python, Go, PHP, or Rust code.
Verify JWT signatures (HMAC) and validate claims — all client-side.
Parse and test robots.txt rules against URLs to check crawler access.
Parse Content Security Policy headers and analyze for security issues.
Compare HTTP headers side by side and highlight differences.
Analyze security headers with pass/warn/fail scoring and remediation guidance.
Paste an OpenAPI spec and generate mock responses for each endpoint.
Convert docker run commands into docker-compose.yml service definitions.
Parse and analyze logs locally. Supports JSON Lines, plain text, and common log formats.
Query and transform JSON using the powerful jq language
Redact secrets, tokens, emails, IP addresses, and credentials from logs locally before sharing.
Query YAML and JSON locally with a practical yq-like path subset for config inspection.
Inspect browser HAR exports locally and redact headers, cookies, query strings, bodies, and response content before sharing.
Chain local developer tools into repeatable browser-only recipes with import, export, sharing, and local saves.
Decode SAML requests and responses locally, inspect assertions, attributes, audiences, recipients, and signature material without validating trust.
Parse DER, PEM, Base64, or hex encoded ASN.1 data locally and inspect TLV structure, tag names, lengths, OIDs, strings, and nested containers.