All tools
JWT Decoder & Verifier
Inspect a token's header and payload, check expiry, and verify the signature - HS* with a shared secret, RS*/ES* with a PEM public key. Decoding happens entirely in your browser.
Decoding runs locally. The token is only sent to our server if you press Verify.
More tools
All 16Password Breach Checker
Check if a password appears in a known data breach - privately. Hashed in your browser, only a five-character prefix is sent (k-anonymity).
One-Time Secret
Share a password or note via a link that self-destructs after one view. Encrypted in your browser - the key never reaches the server.
Email Validator
Check an email address: valid syntax, a live MX-record lookup to see if the domain accepts mail, and disposable or role-based flags.
