Articles
Developer tools
JWT, JSON, hashes and other everyday developer utilities, explained.
5 articles
- Developer
Is it safe to decode a JWT online?
Decoding a JWT's header and payload needs no network request at all - it is just base64 decoding plus JSON parsing, and a tool that genuinely does this client-side never sends your token anywhere. Whether a specific tool actually does that is a separate question worth checking, since not every "online" tool is transparent about it.
- Developer
How to check if a JWT is expired
Paste the token into the JWT Expiry Calculator - it reads the "exp" claim (a Unix timestamp) and shows a plain status (Valid, Expired, or Not yet valid), the exact date and time in your time zone and UTC, and a live countdown, so there is no timestamp math to do by hand.
- Developer
How to validate JSON online for free
Paste the JSON in - if it is invalid, the exact line and column of the problem is shown, so you do not have to scan the whole document by eye. Valid JSON is also pretty-printed for readability.
- Developer
How to generate a SHA-256 checksum online
Paste the text in and a SHA-256 (or SHA-1, SHA-384, SHA-512) hash is generated instantly, entirely in your browser using the Web Crypto API - nothing is uploaded. MD5 is not offered, since it is cryptographically broken and SHA-256 is the appropriate modern replacement for the same job.
- Developer
How many characters should a password be?
At least 16 characters for ordinary accounts, per current guidance from CISA and similar bodies - longer is better, and modern NIST guidance allows passwords up to 64 characters. Length matters more than symbol variety for resisting brute-force attacks.
