Developer tools: JSON, Base64, JWT, hashes, UUIDs and timestamps

Everything here runs on your device. Your files and text are not uploaded.

Choose a tool

  • Hash Generator: Get SHA-256, SHA-1, SHA-384 and SHA-512 of text or a file. Runs on your device.
  • JSON CSV Converter: Convert JSON to CSV and back. Your data stays on your device.
  • JSON Formatter: Format, check or minify JSON. Runs on your device.
  • JWT Decoder: Read a JWT's header, claims and expiry. Runs on your device.
  • Number Base Converter: Binary, octal, decimal, hex and bases 2 to 36. Runs on your device.
  • Text Encoder: Encode and decode Base64, URLs and HTML entities. Handles emoji.
  • Timestamp Converter: Convert Unix timestamps to dates and back. Runs on your device.
  • UUID Generator: Generate random v4 or time-ordered v7 UUIDs. Runs on your device.

About these tools

These tools cover small jobs that come up while building or debugging software. The JSON Formatter formats, minifies and checks JSON against RFC 8259, reports the line and column of the first error, and keeps long numbers as you wrote them. The JSON CSV Converter turns an array of objects into a table and back, flattening nested objects into dot keys. The Text Encoder handles Base64, URL text and HTML entities as UTF-8, so accents and emoji survive, and can turn a small file into a data URI. The JWT Decoder shows a token's header, claims and expiry time. The Hash Generator gives the SHA-256, SHA-1, SHA-384 and SHA-512 of text or a file so you can compare it with a published checksum. The UUID Generator makes random v4 or time-ordered v7 identifiers. The Number Base Converter moves whole numbers between binary, octal, decimal, hexadecimal and bases 2 to 36, and the Timestamp Converter turns Unix timestamps into dates and back.

Everything runs in your browser tab. The JSON, tokens, text and files you add are not sent to a server, hashing uses the browser's own crypto functions, and UUIDs come from its secure random numbers. Decoding a JWT only reads it: the tool does not check the signature, so a decoded token is not proof that it is genuine.

Frequently asked questions

Does the JWT decoder check the signature?

No. It decodes the header and payload, which anyone can read, and shows exp, nbf and iat as dates. It does not verify the signature, so a decoded HS256 or RS256 token is not proof that the token is genuine.

Is my JSON, token or file sent anywhere?

No. Formatting, decoding and hashing all happen in your browser tab, so a 1 MB JSON file or a token you paste is never sent to a server.

Why does my SHA-256 not match the one on the download page?

Most often the file differs by a byte, for example because the line endings changed. The Hash Generator hashes a file byte for byte, up to 100 MB on a computer and 50 MB on a phone.

Which UUID version should I use?

Version 4 is 122 random bits, which suits an ID that only has to be unique. Version 7 starts with the time in milliseconds, so IDs sort in the order they were made, but each one shows when it was made. The generator makes up to 1,000 at a time.