Skip to content

Developer tools

JSON, Base64, hashes, JWT, timestamps and code formatters, all running locally.

Tools in this category

Encoding text is not the same as encrypting it, and calculating a hash is not the same as either. This guide distinguishes the real operations in the catalog -- formatting, validating, minifying, encoding and generating hashes -- so you pick the one you actually need.

Format, validate and minify

Formatting adds indentation and line breaks so a JSON, HTML or CSS document is readable; validating checks whether the content is syntactically correct and, if it isn't, points to where it fails; minifying strips unnecessary whitespace and line breaks to reduce file size, without changing its meaning. These are three distinct operations: formatting and minifying don't repair a JSON or code with syntax errors, they only rearrange whitespace -- if the content isn't valid, the tool surfaces the error instead of trying to fix it on its own. If you just need to explore a large JSON's structure without formatting it, the tree viewer shows it hierarchically, with collapsible nodes.

Format JSON

Validate JSON

Minify JSON

Format HTML

Format CSS

Encode, escape and transform

Base64 encodes any text (with full UTF-8 support) into a 64-character alphabet safe to embed in JSON, emails or URLs -- it's reversible with no key at all, so anyone can decode it: it's not a way to protect or hide information, only to represent it in a different format. URL encoding (percent-encoding) is a different operation: it replaces special characters with %XX sequences so a text can travel inside a URL without breaking it. Don't confuse the two: Base64 output and percent-encoded output look and behave differently, and one tool doesn't substitute for the other.

Encode Base64

Decode Base64

Encode for URL

Decode URL

Hashes, identifiers and irreversible operations

A hash (SHA-256 or MD5) isn't an encoding: it turns text of any length into a fixed-length fingerprint, and that operation has no way back -- there's no such thing as "decrypting a hash" because a hash never encrypted anything, it only summarizes. SHA-256 is computed with the browser's Web Crypto API; MD5 uses a JavaScript implementation and, while still irreversible in practice, is an algorithm with known collisions that shouldn't be used for anything depending on real security, such as storing passwords. The JWT decoder shows a token's header and payload (they're JSON encoded in Base64URL, not encrypted), but it doesn't check the signature: decoding a JWT here doesn't certify it's valid or hasn't been tampered with, it only lets you read its content.

Generate a SHA-256 hash

Generate an MD5 hash

Decode a JWT

Unix timestamp converter

How to choose the right tool

If you need a JSON, HTML or CSS document to be readable or want to confirm it's error-free, use format or validate, not a hash generator. If you need to carry a text inside another format (a URL, a JSON field), use Base64 or URL encoding depending on context. If you need to check content hasn't changed, or generate a verification fingerprint, use a hash -- but remember a hash doesn't let you recover the original text. If you work with regular expressions, the regex tester runs the pattern inside an isolated Web Worker, protected against patterns that would hang the tab with excessive backtracking.

Test regular expressions

Privacy and limits

All 15 tools in this category process text in your browser: nothing you paste (JSON, HTML, CSS, a JWT token, text to encode or hash) is sent to any server. The HTML and CSS formatters use the real Prettier engine, which requires syntactically valid code to format it; if the code has errors, the tool reports them instead of forcing a result.

Frequently asked questions

Does Base64 encoding protect my information?

No. Base64 is reversible with no key at all: anyone can decode it. It represents data in a text-safe format for certain contexts (JSON, URLs, emails), not to hide or protect it.

Can I recover the original text from a SHA-256 or MD5 hash?

No. A hash is a one-way operation: it summarizes text into a fixed-length fingerprint, but that fingerprint doesn't contain the information needed to reconstruct the original text.

Is MD5 suitable for storing passwords securely?

No. MD5 is an algorithm with known collisions and isn't designed to resist modern attacks; it shouldn't be used to store passwords or for anything depending on real cryptographic security.

Does decoding a JWT here confirm it's valid?

No. The decoder shows the header and payload content, but it doesn't verify the signature. A JWT can be decoded and read even if its signature is invalid or it has been tampered with.

What's the difference between formatting and validating a JSON?

Formatting gives visual structure (indentation, line breaks) to an already-valid JSON. Validating checks whether the JSON is syntactically correct and, if not, points to the error. Formatting doesn't fix an invalid JSON.

Are Base64 and URL (percent) encoding the same thing?

No. They're two different encodings with different alphabets and uses: Base64 represents binary data or text in 64 characters, while URL encoding replaces special characters with %XX sequences so a text can fit inside a URL.