Which one you want
- The JSON in your log is one long lineJSON formatter
- You want to see what a regular expression matchesRegular expressions
- You are not sure when a cron line actually runscron
- You need to see what is inside a tokenJWT
- You need to find what differs between two filesDiff
- You are about to paste something into an AI toolSecret scan
- You want the token count and the costToken count
Tools in Dev tools
24 tools
- JSON formatter🌐Format, validate, minify
- SQL formatter🌐Line a query up
- JS formatter🌐Format and minify JavaScript
- CSS formatter🌐Format and minify stylesheets
- Markdown🌐Strip the asterisks and backticks to plain text
- Base64🌐Encode and decode
- URL encoding🌐Percent-encode and back
- JWT🌐Take a token apart
- Hash🌐MD5 and SHA
- UUID🌐UUID v4·v7 and short IDs
- Secret key🌐A safe random string
- Regular expressions🌐Match as you type
- cron🌐Read a schedule out in words
- Diff🌐Compare two texts line by line
- Timestamp🌐Unix time ↔ date
- Colour🌐HEX·RGB·HSL and contrast
- Number base converter🌐Binary, octal, decimal, hex and any base
- Subnet calculator🌐A CIDR block into range, mask and host count
- Favicon🌐Make a favicon from an image
- JSON → TS🌐Derive types from a JSON sample
- Token count🌐Tokens and a cost estimate
- Prompt template🌐Fill the blanks with values
- Function-call schema🌐Build a schema from a sample JSON
- Secret scan🌐Sweep for keys and personal data before pasting into an AI
All twenty-four run inside the browser
None of the twenty-four tools in this group sends anything to a server. Hashes come from the browser's SubtleCrypto, and tokens are counted by a tokenizer downloaded into the browser. For the secret scan there is no other way that makes sense — sending a secret to someone else's server to see whether it leaks is a contradiction. Once the page has loaded, what you paste lives in that tab and nowhere else.
One tool's output is the next one's input
A JWT is three Base64-wrapped JSON pieces joined with dots, so if the payload the JWT tool shows you looks off, you can follow the same route by hand through the Base64 and JSON tools. The exp in it is a timestamp in seconds; drop it into the time tool and you can read when it expired. Two logs filtered with the regex tool go into the diff tool to see what changed.
Where people get caught
Base64 works on bytes, so feeding a browser non-Latin text directly throws. Here the text is converted to UTF-8 first so that error does not appear, but if a value made elsewhere decodes to garbage, suspect the encoding first. Timestamps in seconds and milliseconds are confused a thousandfold all the time, so the time tool guesses from the digit count and says on screen which it assumed. The JWT tool does not verify signatures — asking you to paste a secret key into a web page would teach a bad habit — it only reads what is inside.
Before you paste into an AI
Keys slip into code and logs pasted into AI tools all the time, and once sent they cannot be taken back. The secret scan finds and masks things with a fixed shape: OpenAI, GitHub and AWS keys, private keys, Korean ID and card numbers. Internal tokens with no fixed shape pass through, so a clean result is not a guarantee. The token counter uses OpenAI's o200k_base, so figures for Claude and Gemini are approximations, and because prices change constantly you enter the rate yourself.
Common questions
Does what I paste get uploaded?
No. Formatting, encoding, hashing and comparing all finish inside the browser, and this site has no server to receive anything. That is the premise for using it where tokens or customer data are involved.
Does it work on a locked-down company network?
Once the page has loaded, the work happens in the browser, so yes. Fonts and ads are fetched from outside, so if those are blocked the page may look a little different.
Where do the logs in the error dictionary come from?
They were reproduced in a Docker container rather than copied from somewhere. Each entry records which image was used and how it was reproduced.
Will the output behave the same as the original?
Formatting and minifying use widely used libraries as they are. Even so, run minified code once before you ship it — that check is left to you.