Dev tools

Small tools for everyday development

Formatters for JSON, SQL, JS and CSS, plus Base64, JWT, hashes, UUIDs, regular expressions and cron — the things you need for a minute in the middle of something else.

What you paste is usually something nobody else should see — a token, a key, customer data — so every operation finishes inside the browser. Nothing is uploaded, which also means it works on a locked-down company network. An error dictionary, where every log was actually reproduced, sits alongside them.

Which one you want

Tools in Dev tools

24 tools

All twenty-four run inside the browser

None of the twenty-four tools in this group sends anything to a server. Hashes come from the browser's SubtleCrypto, and tokens are counted by a tokenizer downloaded into the browser. For the secret scan there is no other way that makes sense — sending a secret to someone else's server to see whether it leaks is a contradiction. Once the page has loaded, what you paste lives in that tab and nowhere else.

One tool's output is the next one's input

A JWT is three Base64-wrapped JSON pieces joined with dots, so if the payload the JWT tool shows you looks off, you can follow the same route by hand through the Base64 and JSON tools. The exp in it is a timestamp in seconds; drop it into the time tool and you can read when it expired. Two logs filtered with the regex tool go into the diff tool to see what changed.

Where people get caught

Base64 works on bytes, so feeding a browser non-Latin text directly throws. Here the text is converted to UTF-8 first so that error does not appear, but if a value made elsewhere decodes to garbage, suspect the encoding first. Timestamps in seconds and milliseconds are confused a thousandfold all the time, so the time tool guesses from the digit count and says on screen which it assumed. The JWT tool does not verify signatures — asking you to paste a secret key into a web page would teach a bad habit — it only reads what is inside.

Before you paste into an AI

Keys slip into code and logs pasted into AI tools all the time, and once sent they cannot be taken back. The secret scan finds and masks things with a fixed shape: OpenAI, GitHub and AWS keys, private keys, Korean ID and card numbers. Internal tokens with no fixed shape pass through, so a clean result is not a guarantee. The token counter uses OpenAI's o200k_base, so figures for Claude and Gemini are approximations, and because prices change constantly you enter the rate yourself.

Common questions

Does what I paste get uploaded?

No. Formatting, encoding, hashing and comparing all finish inside the browser, and this site has no server to receive anything. That is the premise for using it where tokens or customer data are involved.

Does it work on a locked-down company network?

Once the page has loaded, the work happens in the browser, so yes. Fonts and ads are fetched from outside, so if those are blocked the page may look a little different.

Where do the logs in the error dictionary come from?

They were reproduced in a Docker container rather than copied from somewhere. Each entry records which image was used and how it was reproduced.

Will the output behave the same as the original?

Formatting and minifying use widely used libraries as they are. Even so, run minified code once before you ship it — that check is left to you.

Categories