MyAITools
myaitools.net

// 143 developer & data tools — paste, transform, copy

Paste. Transform. Copy. The dev console for the utilities you reach for mid-task.

120+ encoders, JSON tools, hashers, regex testers, formatters, Mermaid renderers and payment-data decoders — all client-side. Your keys, tokens and payloads never leave the tab.

Six families, one keystroke away

Grouped the way you think about them, not by file type.

Every tool here exists because a developer hit a wall mid-task: a token that wouldn't decode, JSON that wouldn't parse, a regex that matched everything except the one case that mattered. The catalog is organized into the families you actually search for — encoders, structured-data tooling, cryptographic primitives, pattern matching, code formatters, and payment-data decoders. Pick a family, land on a tool, paste your input, read the output. There is no project to create, no API key to provision, and no rate limit waiting to bite you on the tenth request. Each transform is a pure function of what you paste: same input, same output, no hidden server state, no session cookie deciding what you're allowed to see. Treat the whole catalog like a local bin/ directory you didn't have to install.

Encoders & decoders

Base64, Base32, URL, HTML entities, hex and binary — round-trip any of them. Paste a Base64 blob and read it back, or encode a string for a query param. Each codec is its own page, so you can deep-link the exact transform from a ticket or a script comment.

JSON & structured data

Format, validate, diff, flatten, and generate types from a sample payload. Turn an API response into a TypeScript interface, a Go struct, or a JSON Schema without leaving the browser. Validation reports the line and column of the first syntax error instead of a vague 'unexpected token'.

Hashing & crypto

SHA-256, SHA-1, MD5, HMAC signatures and bcrypt hashes computed in-page. Verify a release checksum, sign a webhook body to match what your server expects, or hash a candidate string to confirm a stored digest. The Web Crypto API does the heavy lifting natively.

Regex & pattern matching

Test a pattern against live input with match highlighting and named capture groups before you paste it into code. Tweak a character class and watch the matches repaint — no more print-debugging your quantifiers one console.log at a time.

Formatters & beautifiers

SQL, XML, YAML, CSS, JS and HTML — pretty-print minified output or normalize a messy query into something diff-able and reviewable. Paste the one-line blob your build emitted and get back indentation a reviewer can actually read in a pull request.

Payment-data utilities

Decode EMV TLV chip data into named tags, look up BINs and MCCs, validate IBANs and Luhn-check PANs. Niche tooling that's hard to find anywhere else, built for the engineer staring at a hex dump from a terminal log at 2am.

The loop, with zero ceremony

Paste → transform → copy. Three steps, no account, no upload.

The whole interaction is a read-eval-print loop you already know from the shell. You paste, the page evaluates locally, you read the result, you copy it back into whatever you were doing. No build step, no npm install, no auth handshake standing between you and the answer. Because every step runs against the JavaScript engine in the tab you already have open, there's nothing to wait on — the transform is bound by your CPU, not a round-trip to someone else's server. Keep the tab pinned and it behaves like a scratchpad that's always one keystroke from whatever encode/decode/hash you need next.

  1. 1

    1 · Paste your input

    Drop a token, a JSON blob, a string, a raw query or a Mermaid definition straight into the input field. No request fires on paste — the data lands directly in the in-browser engine's scope and goes nowhere else. Your clipboard is the only thing that touched it.

  2. 2

    2 · Transform in the browser

    Encoding, hashing, formatting and parsing run as JavaScript or WebAssembly on your own machine. Output updates as you type, so you can flip a flag, fix a regex, or reshape a payload and watch the result recompute live without re-submitting anything.

  3. 3

    3 · Copy and move on

    One click copies the result to your clipboard. No watermark, no 'sign up to export,' no truncated free-tier output. Close the tab and the in-memory data is gone with it — nothing was persisted because nothing was ever sent.

Spotlight: JWT Decoder

The one you'll bookmark first.

A JSON Web Token looks like three Base64url chunks joined by dots: header.payload.signature. The decoder splits on the dots, Base64url-decodes the header and payload, and pretty-prints the claims so you can read exp, iat, iss, aud and your custom fields at a glance — exactly what you want when an auth flow returns a 401 and you need to know whether the token is malformed, expired, or scoped wrong before you start blaming the gateway.

The important part: decoding is not verifying. Anyone can read a JWT's payload because Base64url is encoding, not encryption — the signature is what proves the token wasn't tampered with, and verifying it requires the issuer's secret (HS256) or public key (RS256). So treat the payload as readable-but-untrusted, never put secrets in it, and always verify the signature server-side before you act on a claim. Because the decoder is pure client-side JavaScript, pasting a production token to inspect it doesn't ship it to a third-party API — no request fires, and the token never leaves the tab. You can confirm that yourself: open DevTools, watch the Network panel stay silent while the claims render. Pair it with the HMAC generator when you're debugging an HS256 signature mismatch, or the Base64 tools when a single chunk refuses to decode and you want to inspect the raw bytes by hand.

Encoding vs. hashing vs. encryption

The distinction that trips up more code reviews than it should.

These three get used interchangeably in bug reports and Slack threads, and they are not the same operation. Encoding is a reversible format change with no secret — Base64 exists to move binary safely through text channels, and anyone can decode it. Hashing is a one-way fingerprint — you can't recover the input, which is exactly why it's right for password storage (bcrypt) and integrity checks (SHA-256), and exactly why it's wrong for anything you need to read back. Encryption is reversible but only with a key — it's the one of the three that actually provides confidentiality. Reach for the wrong one and you either leak data you assumed was protected or permanently lock yourself out of data you needed back. The table below is the cheat sheet to paste into your next design review when someone says 'just Base64 it' about a password.

OperationReversible?Needs a key?Use it forTool
Base64 encodeYes — anyoneNoTransport-safe text, data URIs, token segmentsbase64-encode
URL encodeYes — anyoneNoQuery strings, path segments, form bodiesurl-encode
SHA-256 hashNoNoIntegrity checks, content fingerprintshash-text
HMACNoYes (shared secret)Signing webhooks & API requestshmac-generator
bcryptNo (verify only)No (salt embedded)Password storage & verificationbcrypt-hash

Browse by category

Four lanes covering the full catalog.

If you'd rather scan than search, the 120+ tools sort into four lanes. Text and encoding is the deepest — it's where the day-to-day codecs and crypto primitives live. Developer utilities covers the formatters and network-math helpers you reach for during a debugging session. Diagrams turns a Mermaid definition into a file you can attach to a README. Payment data is the specialist corner most generic tool sites skip entirely. Every lane links straight to a working tool, so browsing the category is one click from actually running the transform.

What you're working with

120+

developer & data tools across four categories

0

uploads — every transform runs in your browser

No sign-up

no account, no API key, no rate limit

10

in-depth field guides on the concepts behind the tools

Field guides

The why behind the tools — read these once and stop second-guessing.

All guides →

Short, practical write-ups for the questions that come up at the keyboard: what Base64 actually does to your bytes, why a JWT payload is readable by anyone holding the string, when to reach for a UUID versus a ULID, and how bcrypt's work factor protects a password database. No filler, no SEO padding — each guide is the explanation you'd want from the senior engineer who already debugged this once. Every one links straight to the matching tool, so you can run the transform in one tab while you read about it in the other.

Why client-side matters here

Most of what you'll paste into these tools is sensitive: a production JWT, an API key you're HMAC-signing, a customer's PAN, a JSON payload thick with PII. On the typical 'online tool' site, that input is POSTed to a server you don't control, parsed by code you can't read, and logged somewhere you'll never audit. For a developer toolbox that handles credentials, that's an unacceptable default — it turns a quick decode into a data-egress event.

So the transforms here are wired the other way around: they run against the JavaScript engine in your tab. Encoding, decoding, hashing, JSON formatting, regex matching and Mermaid rendering all execute locally — no request fires, and the key never leaves the tab. You don't have to take that on faith. Open DevTools, switch to the Network panel, and run any text transform: you'll watch the request list stay empty while the output updates. It's the same reason these tools keep working with your wifi off once the page has loaded, and the same reason there's no account to create — there's no server-side session to attach you to in the first place.

The honest caveat: a few file-output tools (rendering a Mermaid diagram to PDF, for instance) do heavier lifting and are labeled accordingly. The rule of thumb stays simple — the paste-and-transform text utilities are pure client-side, and your tokens, keys and payloads stay in the tab where you typed them.

Open a tab, paste, ship

Bookmark the three you'll use daily.

JSON Formatter

The full toolbox

Every encoder, formatter, hash and decoder — search or browse.

Frequently asked

Do my tokens, keys and payloads get uploaded anywhere?

No. The paste-and-transform text utilities — encoding, decoding, hashing, HMAC, JSON formatting, regex testing — run entirely in your browser as JavaScript or WebAssembly, so no request fires and the input never leaves the tab. You can verify it directly: open DevTools, switch to the Network panel, and run a transform — the request list stays empty while the output updates. A few file-output tools do heavier work and are labeled as such.

What's the difference between decoding a JWT and verifying it?

Decoding just Base64url-decodes the header and payload so you can read the claims — anyone can do this, because a JWT's payload is encoded, not encrypted. Verifying recomputes the signature using the issuer's secret (HS256) or public key (RS256) and confirms the token wasn't tampered with. The decoder here reads claims; always verify the signature server-side before trusting any claim, and never put secrets in the payload.

Is Base64 a form of encryption?

No — it's encoding, fully reversible by anyone with no key. Base64 exists to represent binary data safely as text (for data URIs, email attachments, token segments), not to hide it. If you need confidentiality, use encryption; if you need a one-way fingerprint for integrity or password storage, use a hash like SHA-256 or bcrypt.

When should I use HMAC versus a plain hash?

Use a plain hash (SHA-256, or MD5 for legacy checksums) when you just need a fingerprint of public data — file integrity, content addressing. Use HMAC when you need to prove the data came from someone holding a shared secret, such as signing a webhook body or an API request so the receiver can confirm it wasn't forged. HMAC is a keyed hash; a plain hash has no key and anyone can recompute it.

Why is bcrypt slow, and is that a bug?

It's the whole point. bcrypt has a tunable work factor (cost) that makes each hash deliberately expensive to compute, so an attacker who steals your password database can only test a few thousand guesses per second instead of billions. Raise the cost as hardware gets faster. To verify a password you don't recompute and compare strings — you feed the candidate and the stored hash to bcrypt's verify, which extracts the embedded salt and cost automatically.

Can I decode EMV chip data and other payment fields here?

Yes — this site carries payment-data utilities that are genuinely hard to find elsewhere: an EMV TLV decoder that parses tag-length-value chip data into named EMV tags, plus EMV tag lookup, BIN and MCC lookups, IBAN and SWIFT/BIC validation, Luhn (mod-10) checks and card-brand identification. They run in the browser like the rest of the toolbox.

Do these tools work offline?

Largely, yes. Because the text transforms execute client-side, once a tool's page has loaded you can keep encoding, hashing, formatting and testing regex with no network connection. There's no server round-trip and no session, which is also why there's nothing to sign up for.

Should I use a UUID or a ULID for my IDs?

Use a UUID v4 when you want a purely random, collision-resistant identifier and ordering doesn't matter. Reach for a ULID when you want IDs that sort lexicographically by creation time — they embed a millisecond timestamp prefix, which makes them friendlier for database indexes and cursor pagination. The UUID generator covers the random case; the field guide walks through the trade-off.