Password Generator
Generate random passwords or word passphrases in your browser.
Helpers for keeping accounts and files in order. Create a strong password with the rules you need, or calculate a hash or checksum to confirm a file has not changed. Both run on your device, so a password or a file never leaves your browser.
40 tools in this part of the catalogue.
Generate random passwords or word passphrases in your browser.
Generate random passwords or word passphrases in your browser.
Get a local, dictionary-based estimate of a password's strength.
Hash text or files and compare a supplied checksum.
Sign a message with HMAC and verify a signature.
Generate SRI attributes from exact local bytes.
Verify files against a checksum list.
Compare local file hashes and recorded paths.
Build a file tree and verify an inclusion proof.
Draft a Content Security Policy from a strict baseline.
Inspect pasted HTTP headers and check security fields.
Unfold message headers and read SPF, DKIM and DMARC.
Draft and explain an explicit CORS policy.
Explain cookie attributes while masking values.
Review declared OAuth client redirects and settings.
Model referrer disclosure for entered URLs.
Model selected feature delegation to one iframe.
Group supplied CSP reports with URL detail omitted.
Review supplied mail-auth records without DNS.
Review supported SSH client options offline.
Review an entered role and permission matrix.
Compare declared SBOM components and versions.
Mask sensitive text or chosen CSV columns.
Replace selected identifiers in local CSV.
Inspect a URL without opening its target.
Inspect authorization-code and PKCE inputs.
Generate one local authenticator code.
Encrypt or restore one local file.
Find password reuse without exporting passwords.
Check listed terms remaining after text redaction.
Find secret patterns without showing matched values.
Inspect public PGP packet metadata.
Read public certificate and CSR metadata.
Inspect public JSON keys and calculate thumbprints.
Inventory public certificate dates and duplicates.
Inspect public SSH keys and declared restrictions.
Compare recorded host-key pins without connecting.
Decode public WebAuthn response metadata.
Check JWS signatures with a supplied public key.
Verify exact bytes and a detached public-key signature.
Read a JWT header and payload, with claims shown as dates.