VSThiran

Free developer tools

Free developer tools that keep your data local

Format and measure JSON, decode JWTs and check when they expire, size API rate limits and responses, translate cron expressions, encode Base64, generate hashes and create strong passwords. Everything runs in your browser, because these are exactly the tools people paste secrets into.

All developer tools

Showing 10 of 10 developer tools

Technology & Developers

Base64 Encoder / Decoder

Encode text to Base64 or decode it back, including Unicode and emoji.

Open tool
Technology & Developers

JSON Formatter

Beautify, minify and validate JSON, with real error messages.

Open tool
Technology & Developers

Hash Generator

Generate SHA-1, SHA-256, SHA-384 and SHA-512 hashes as you type.

Open tool
Technology & Developers

Password Generator

Create strong random passwords that never leave your browser.

Open tool
Technology & Developers

JWT Decoder

Paste a JWT to see its header and payload, check its expiry, and optionally verify its signature - entirely in your browser.

Open tool
Technology & Developers

API Rate Limit Calculator

Convert a rate limit between time windows, check your request rate against it, and size the limit your users actually need.

Open tool
Technology & Developers

API Response Size Calculator

Estimate how big each API response is, how much compression saves, and how much data and bandwidth your traffic uses.

Open tool
Technology & Developers

JSON Size Calculator

Paste or load JSON to see its exact size in bytes - as written, minified, pretty-printed and gzipped - and whether it is valid.

Open tool
Technology & Developers

JWT Expiry Calculator

Decode a JWT’s time claims to see when it was issued, when it becomes valid, when it expires and how long it has left.

Open tool
Technology & Developers

Cron Expression Translator

Type a cron expression to see what it means in plain English, what each field matches and exactly when it will run next.

Open tool

These are the small utilities that come up several times a week: decoding a Base64 token or a JWT, making sense of an API response, checking a file hash, reading a cron schedule, generating a password that is not a variation of the last one - and the back-of-envelope sums behind API planning, such as how a rate limit converts between windows or how much data an endpoint will move in a month.

Every one of them runs entirely in your browser. That is not a marketing line here - it is the whole point. Developer tools are where people paste API keys, JWTs, connection strings and customer records, usually without pausing to think about where that data is going.

Which developer tool do you need?

  • To encode or decode Base64 - including URL-safe input and full Unicode - use the free Base64 encoder and decoder.
  • To make an API response readable, or find the syntax error in a config file, use the free JSON formatter and validator.
  • To verify a download or compare two files, use the free hash generator for SHA-256, SHA-384 and SHA-512.
  • To create a strong unique password, use the free password generator, which uses your browser's cryptographic randomness rather than Math.random.
  • To read the claims inside a JSON Web Token, use the JWT decoder; to see exactly when a token expires and how long it has left, use the JWT expiry calculator.
  • To measure how many bytes a JSON document takes - raw, minified and compressed - use the JSON size calculator.
  • To estimate how big an API response is and how much data and bandwidth your traffic uses per day and month, use the API response size calculator.
  • To convert a rate limit between per-second, per-minute, per-hour and per-day figures, or work out the limit your users need, use the API rate limit calculator.
  • To turn a cron expression into plain English and see when it next runs, use the cron expression translator.

Why local processing matters here specifically

Think about what actually gets pasted into these tools. A JSON formatter receives API responses containing customer names, email addresses and access tokens. A Base64 decoder receives session tokens and credentials. A hash generator sometimes receives the very string someone is trying to keep secret.

Sending any of that to a third-party server to be reformatted is a poor trade. None of these operations need a server: your browser can parse JSON, encode Base64 and compute a SHA-256 digest natively and instantly. So that is where it happens, and there is no request that could carry your data anywhere.

What these tools deliberately do not offer

  • MD5 hashing. Browsers do not provide it, and it has been cryptographically broken for two decades. SHA-256 is the right answer.
  • Hash "decryption". Hashing is one-way; sites claiming to reverse it are searching tables of pre-computed common values.
  • JWT signature verification. Decoding shows what a token claims; only a server holding the key can confirm the signature is genuine.
  • Password storage or history. Generated passwords exist only until you close the tab, by design.
  • Any claim that Base64 is secure. It is an encoding, not encryption, and anyone can decode it instantly.

Frequently asked questions

Are these developer tools free?

Yes - all of them, with no sign-up, no rate limit and no premium tier.

Is my data sent to a server?

No. Everything runs in your browser. Nothing you paste is uploaded, logged or retained - which is the main reason to use these rather than an equivalent that round-trips through someone else's backend.

Is Base64 a form of encryption?

No. It is an encoding designed to let binary data travel through text-only channels. Anyone can decode it in a second, with no key. Never use it to protect a secret.

Why is MD5 not offered in the hash generator?

Browsers do not provide MD5 through Web Crypto, and it has been unsuitable for security work since the 1990s. Adding a third-party implementation to offer a broken algorithm is not a trade worth making.

How random are the generated passwords?

They use crypto.getRandomValues, the browser's cryptographically secure generator, with rejection sampling so no character is favoured over another.

Can I use these offline?

The developer tools and calculators here do their work with code already on the page, so once a page has loaded it keeps working without a connection. The PDF and image tools do fetch a library on first use, so they need a connection for that first run.