Tool category

Security & Hashing Tools

Security-related input such as tokens and passwords is exactly the kind of data you should not paste into a site that uploads it. These tools use the browser's Web Crypto API and run locally, so the values you inspect or generate stay on your device.

Decoding is not verifying

The JWT Decoder shows a token's header and claims, which is useful for checking expiry or scopes. It does not verify the signature; only the service holding the signing key can confirm a token is genuine.

Hashes and passwords

SHA-256 is suited to checksums and integrity checks. For storing user passwords, use a deliberately slow algorithm such as Argon2 or bcrypt on your server. Generated passwords use cryptographic randomness, not Math.random().