MyAITools
myaitools.net

// 143 developer & data tools — paste, transform, copy

Paste. Transform. Copy. The dev console for the utilities you reach for mid-task.

120+ encoders, JSON tools, hashers, regex testers, formatters, Mermaid renderers and payment-data decoders — all client-side. Your keys, tokens and payloads never leave the tab.

Six families, one keystroke away

Grouped the way you think about them, not by file type.

Every tool here exists because a developer hit a wall mid-task: a token that wouldn't decode, JSON that wouldn't parse, a regex that matched everything except the one case that mattered. The catalog is organized into the families you actually search for — encoders, structured-data tooling, cryptographic primitives, pattern matching, code formatters, and payment-data decoders. Pick a family, land on a tool, paste your input, read the output. There is no project to create, no API key to provision, and no rate limit waiting to bite you on the tenth request. Each transform is a pure function of what you paste: same input, same output, no hidden server state, no session cookie deciding what you're allowed to see. Treat the whole catalog like a local bin/ directory you didn't have to install.

Encoders & decoders

Base64, Base32, URL, HTML entities, hex and binary — round-trip any of them. Paste a Base64 blob and read it back, or encode a string for a query param. Each codec is its own page, so you can deep-link the exact transform from a ticket or a script comment.

JSON & structured data

Format, validate, diff, flatten, and generate types from a sample payload. Turn an API response into a TypeScript interface, a Go struct, or a JSON Schema without leaving the browser. Validation reports the line and column of the first syntax error instead of a vague 'unexpected token'.

Hashing & crypto

SHA-256, SHA-1, MD5, HMAC signatures and bcrypt hashes computed in-page. Verify a release checksum, sign a webhook body to match what your server expects, or hash a candidate string to confirm a stored digest. The Web Crypto API does the heavy lifting natively.

Regex & pattern matching

Test a pattern against live input with match highlighting and named capture groups before you paste it into code. Tweak a character class and watch the matches repaint — no more print-debugging your quantifiers one console.log at a time.

Formatters & beautifiers

SQL, XML, YAML, CSS, JS and HTML — pretty-print minified output or normalize a messy query into something diff-able and reviewable. Paste the one-line blob your build emitted and get back indentation a reviewer can actually read in a pull request.

Payment-data utilities

Decode EMV TLV chip data into named tags, look up BINs and MCCs, validate IBANs and Luhn-check PANs. Niche tooling that's hard to find anywhere else, built for the engineer staring at a hex dump from a terminal log at 2am.

The loop, with zero ceremony

Paste → transform → copy. Three steps, no account, no upload.

The whole interaction is a read-eval-print loop you already know from the shell. You paste, the page evaluates locally, you read the result, you copy it back into whatever you were doing. No build step, no npm install, no auth handshake standing between you and the answer. Because every step runs against the JavaScript engine in the tab you already have open, there's nothing to wait on — the transform is bound by your CPU, not a round-trip to someone else's server. Keep the tab pinned and it behaves like a scratchpad that's always one keystroke from whatever encode/decode/hash you need next.

  1. 1

    1 · Paste your input

    Drop a token, a JSON blob, a string, a raw query or a Mermaid definition straight into the input field. No request fires on paste — the data lands directly in the in-browser engine's scope and goes nowhere else. Your clipboard is the only thing that touched it.

  2. 2

    2 · Transform in the browser

    Encoding, hashing, formatting and parsing run as JavaScript or WebAssembly on your own machine. Output updates as you type, so you can flip a flag, fix a regex, or reshape a payload and watch the result recompute live without re-submitting anything.

  3. 3

    3 · Copy and move on

    One click copies the result to your clipboard. No watermark, no 'sign up to export,' no truncated free-tier output. Close the tab and the in-memory data is gone with it — nothing was persisted because nothing was ever sent.

Spotlight: JWT Decoder

The one you'll bookmark first.

A JSON Web Token looks like three Base64url chunks joined by dots: header.payload.signature. The decoder splits on the dots, Base64url-decodes the header and payload, and pretty-prints the claims so you can read exp, iat, iss, aud and your custom fields at a glance — exactly what you want when an auth flow returns a 401 and you need to know whether the token is malformed, expired, or scoped wrong before you start blaming the gateway.

The important part: decoding is not verifying. Anyone can read a JWT's payload because Base64url is encoding, not encryption — the signature is what proves the token wasn't tampered with, and verifying it requires the issuer's secret (HS256) or public key (RS256). So treat the payload as readable-but-untrusted, never put secrets in it, and always verify the signature server-side before you act on a claim. Because the decoder is pure client-side JavaScript, pasting a production token to inspect it doesn't ship it to a third-party API — no request fires, and the token never leaves the tab. You can confirm that yourself: open DevTools, watch the Network panel stay silent while the claims render. Pair it with the HMAC generator when you're debugging an HS256 signature mismatch, or the Base64 tools when a single chunk refuses to decode and you want to inspect the raw bytes by hand.

Encoding vs. hashing vs. encryption

The distinction that trips up more code reviews than it should.

These three get used interchangeably in bug reports and Slack threads, and they are not the same operation. Encoding is a reversible format change with no secret — Base64 exists to move binary safely through text channels, and anyone can decode it. Hashing is a one-way fingerprint — you can't recover the input, which is exactly why it's right for password storage (bcrypt) and integrity checks (SHA-256), and exactly why it's wrong for anything you need to read back. Encryption is reversible but only with a key — it's the one of the three that actually provides confidentiality. Reach for the wrong one and you either leak data you assumed was protected or permanently lock yourself out of data you needed back. The table below is the cheat sheet to paste into your next design review when someone says 'just Base64 it' about a password.

OperationReversible?Needs a key?Use it forTool
Base64 encodeYes — anyoneNoTransport-safe text, data URIs, token segmentsbase64-encode
URL encodeYes — anyoneNoQuery strings, path segments, form bodiesurl-encode
SHA-256 hashNoNoIntegrity checks, content fingerprintshash-text
HMACNoYes (shared secret)Signing webhooks & API requestshmac-generator
bcryptNo (verify only)No (salt embedded)Password storage & verificationbcrypt-hash

Browse by category

Four lanes covering the full catalog.

If you'd rather scan than search, the 120+ tools sort into four lanes. Text and encoding is the deepest — it's where the day-to-day codecs and crypto primitives live. Developer utilities covers the formatters and network-math helpers you reach for during a debugging session. Diagrams turns a Mermaid definition into a file you can attach to a README. Payment data is the specialist corner most generic tool sites skip entirely. Every lane links straight to a working tool, so browsing the category is one click from actually running the transform.

What you're working with

120+

developer & data tools across four categories

0

uploads — every transform runs in your browser

No sign-up

no account, no API key, no rate limit

10

in-depth field guides on the concepts behind the tools

Field guides

The why behind the tools — read these once and stop second-guessing.

All guides →

Short, practical write-ups for the questions that come up at the keyboard: what Base64 actually does to your bytes, why a JWT payload is readable by anyone holding the string, when to reach for a UUID versus a ULID, and how bcrypt's work factor protects a password database. No filler, no SEO padding — each guide is the explanation you'd want from the senior engineer who already debugged this once. Every one links straight to the matching tool, so you can run the transform in one tab while you read about it in the other.

Why client-side matters here

Most of what you'll paste into these tools is sensitive: a production JWT, an API key you're HMAC-signing, a customer's PAN, a JSON payload thick with PII. On the typical 'online tool' site, that input is POSTed to a server you don't control, parsed by code you can't read, and logged somewhere you'll never audit. For a developer toolbox that handles credentials, that's an unacceptable default — it turns a quick decode into a data-egress event.

So the transforms here are wired the other way around: they run against the JavaScript engine in your tab. Encoding, decoding, hashing, JSON formatting, regex matching and Mermaid rendering all execute locally — no request fires, and the key never leaves the tab. You don't have to take that on faith. Open DevTools, switch to the Network panel, and run any text transform: you'll watch the request list stay empty while the output updates. It's the same reason these tools keep working with your wifi off once the page has loaded, and the same reason there's no account to create — there's no server-side session to attach you to in the first place.

The honest caveat: a few file-output tools (rendering a Mermaid diagram to PDF, for instance) do heavier lifting and are labeled accordingly. The rule of thumb stays simple — the paste-and-transform text utilities are pure client-side, and your tokens, keys and payloads stay in the tab where you typed them.

Open a tab, paste, ship

Bookmark the three you'll use daily.

JSON Formatter

The full toolbox

Every encoder, formatter, hash and decoder — search or browse.

qr-code-reader

Text & Encoding

Scan a QR code from any image and decode it to text — free, online, runs entirely in your browser.

mermaid-to-svg

Diagram

Render a Mermaid diagram as a scalable SVG — paste the code or upload an .mmd file.

mermaid-to-png

Diagram

Render a Mermaid diagram as a high-resolution PNG — paste the code or upload an .mmd file.

mermaid-to-jpg

Diagram

Render a Mermaid diagram as a JPG image — paste the code or upload an .mmd file.

mermaid-to-pdf

Diagram

Render a Mermaid diagram as a single-page PDF — paste the code or upload an .mmd file.

qr-code-generator

Text & Encoding

Generate a QR code from any text, URL or contact data — pick error correction and scale, get a PNG.

file-to-hex

Text & Encoding

Convert any file's bytes to a hex dump (with ASCII sidecar), plain hex, C array or comma-separated bytes.

hex-to-file

Text & Encoding

Parse a hex dump or hex string back into a binary file — strips offsets, ASCII columns, prefixes and separators automatically.

wifi-qr-code-generator

Text & Encoding

Generate a Wi-Fi QR code as a PNG — scanning it auto-joins the network. Supports WPA / WEP / open networks and hidden SSIDs.

vcard-qr-code-generator

Text & Encoding

Generate a QR code that contains a digital business card (vCard) — scanning it lets the phone save the contact in one tap.

barcode-generator

Text & Encoding

Generate a 1D barcode (CODE128, EAN-13, UPC-A, CODE39, ITF-14, MSI, codabar, pharmacode) as a downloadable PNG.

base64-encode

Text & Encoding

Encode any text to Base64 (and URL-safe Base64) — runs locally in your browser, free and online.

base64-decode

Text & Encoding

Decode Base64 or URL-safe Base64 strings back to UTF-8 text — runs locally in your browser.

url-encode

Text & Encoding

Percent-encode text for safe use in URLs — supports both encodeURIComponent and encodeURI.

url-decode

Text & Encoding

Decode percent-encoded URL text back to its readable form — supports decodeURIComponent and decodeURI.

jwt-decoder

Text & Encoding

Decode a JSON Web Token to inspect its header and payload — runs locally, your token never leaves the browser.

hash-text

Text & Encoding

Compute MD5, SHA-1, SHA-256, SHA-384 or SHA-512 of any text — runs locally in your browser.

uuid-generator

Text & Encoding

Generate cryptographically random UUIDs (v4) or time-ordered UUIDs (v7) — runs locally in your browser.

json-formatter

Text & Encoding

Pretty-print or minify any JSON document — validates structure and reports parse errors with position.

text-case-converter

Text & Encoding

Convert any string to lowercase, UPPERCASE, Title Case, camelCase, snake_case, kebab-case and more — all at once.

lorem-ipsum

Text & Encoding

Generate placeholder lorem ipsum text — by paragraph, sentence or word count.

prompt-master

Text & Encoding

Turn a rough idea or draft into a copyable prompt for ChatGPT, Claude, Cursor, Midjourney, Sora, Zapier, and more.

html-encode

Text & Encoding

Encode text to HTML entities — escape <, >, &, " and ' (and optionally everything non-ASCII).

html-decode

Text & Encoding

Decode HTML entities back to plain text — handles numeric (&#NNN; / &#xNNN;) and the common named entities.

hex-to-text

Text & Encoding

Decode a hex string back to UTF-8 text — accepts 0x prefixes, spaces, and any case.

text-to-hex

Text & Encoding

Encode UTF-8 text as a hex string — lowercase, uppercase, space-separated or 0x-prefixed.

binary-to-text

Text & Encoding

Decode 8-bit binary (groups of 0/1) back to UTF-8 text — space- or comma-separated.

text-to-binary

Text & Encoding

Encode UTF-8 text as 8-bit binary groups — choose space, comma or no separator.

rot13

Text & Encoding

Apply the ROT13 substitution cipher — letters shift by 13, applying twice returns the original.

caesar-cipher

Text & Encoding

Encrypt or decrypt text with the classic Caesar shift cipher — choose any shift from -25 to 25.

text-reverse

Text & Encoding

Reverse text by character or by word — Unicode-aware so emoji and combining marks stay intact.

text-sort-lines

Text & Encoding

Sort lines alphabetically or numerically, ascending or descending, case-sensitive or not.

text-dedupe-lines

Text & Encoding

Remove duplicate lines from a list — case-sensitive or not, preserve original order or not.

text-counter

Text & Encoding

Count characters, words, lines, sentences, paragraphs and estimate reading time.

slugify

Text & Encoding

Convert any text to a clean, URL-safe slug — strips diacritics and replaces non-alphanumerics.

password-generator

Text & Encoding

Generate cryptographically random passwords — choose length, character classes, and exclude lookalikes.

password-strength-checker

Text & Encoding

Estimate password entropy and crack time — checked entirely locally, nothing uploaded.

random-string-generator

Text & Encoding

Generate batches of random strings — pick charset, length and count, all sourced from crypto.getRandomValues.

random-number-generator

Text & Encoding

Generate uniform random integers in a range — uses crypto.getRandomValues for true uniformity.

json-to-typescript

Text & Encoding

Infer TypeScript interfaces from any JSON payload — nested objects get their own named interface.

regex-tester

Text & Encoding

Test a JavaScript regular expression against sample text — see matches, groups, and a replacement preview.

unix-timestamp-converter

Text & Encoding

Convert between Unix timestamps and human-readable dates — auto-detects seconds vs milliseconds.

crontab-explainer

Text & Encoding

Explain a cron expression in plain English and show the next firing times.

hex-to-decimal

Text & Encoding

Convert a hexadecimal number to decimal — also shows binary and octal. Handles arbitrary-size integers via BigInt.

decimal-to-hex

Text & Encoding

Convert a decimal integer to hexadecimal — also shows binary and octal. Uppercase output with optional 0x prefix.

binary-to-decimal

Text & Encoding

Convert a binary number to decimal — also shows hex and octal. Spaces and underscores ignored.

decimal-to-binary

Text & Encoding

Convert a decimal integer to binary — also shows hex and octal. Group bits by 4 or 8 for readability.

hex-to-binary

Text & Encoding

Convert a hexadecimal number to binary — each hex digit becomes 4 bits, padded. Also shows decimal.

binary-to-hex

Text & Encoding

Convert a binary number to hexadecimal — input is padded to a multiple of 4 bits. Also shows decimal.

base-converter

Text & Encoding

Convert a number between any two bases from 2 to 36 — also shows the value in binary, octal, decimal and hex.

text-to-decimal

Text & Encoding

Encode each character as its Unicode code point in decimal — space-, comma- or newline-separated output.

decimal-to-text

Text & Encoding

Decode a list of decimal Unicode code points back to text — any separator (space, comma, newline) accepted.

text-to-unicode

Text & Encoding

Convert text into Unicode escape sequences — U+XXXX, \uXXXX, &#XXXX; or %uXXXX. Hex digits are uppercase.

unicode-to-text

Text & Encoding

Decode mixed Unicode escapes (U+XXXX, \uXXXX, \u{XXXXX}, \xHH, &#XXXX;, %uXXXX) back to plain text.

base32-encode

Text & Encoding

Encode UTF-8 text to RFC 4648 Base32 — alphabet A-Z and 2-7, with = padding. Useful for TOTP secrets and DNS-safe identifiers.

base32-decode

Text & Encoding

Decode RFC 4648 Base32 (A-Z, 2-7) back to UTF-8 text — case-insensitive, padding optional.

quoted-printable-encode

Text & Encoding

Encode text to Quoted-Printable (RFC 2045) — for email bodies. Non-ASCII bytes become =XX, lines soft-wrap at 76 columns.

quoted-printable-decode

Text & Encoding

Decode Quoted-Printable (RFC 2045) text back to UTF-8 — handles =XX escapes and soft line breaks (=\r\n).

text-to-morse

Text & Encoding

Encode text into international Morse code (ITU-R M.1677-1) — letters, digits and common punctuation supported.

morse-to-text

Text & Encoding

Decode international Morse code (ITU) back to plain text — letters separated by spaces, words by /.

leet-speak

Text & Encoding

Convert text into l33t sp34k — three intensity levels: mild (a→4, e→3, i→1, o→0, s→5, t→7), strong, and maximum.

vigenere-cipher

Text & Encoding

Encrypt or decrypt text with the classic Vigenère cipher using a keyword — runs entirely in your browser.

hmac-generator

Text & Encoding

Compute HMAC-SHA1, HMAC-SHA256, HMAC-SHA384 or HMAC-SHA512 of a message under a secret key — output in hex and base64.

bcrypt-hash

Text & Encoding

Generate a bcrypt hash from a password, or verify a password against an existing bcrypt hash — adjustable cost factor.

rsa-keypair-generator

Text & Encoding

Generate an RSA private/public key pair as PEM (2048, 3072 or 4096-bit) and a SHA-256 fingerprint of the public key.

bip39-mnemonic

Text & Encoding

Generate a BIP39 mnemonic seed phrase (12/15/18/21/24 words) and the corresponding entropy + seed — or convert an existing mnemonic to its seed.

ulid-generator

Text & Encoding

Generate ULIDs — Universally Unique Lexicographically Sortable Identifiers — that double as a sortable timestamp prefix.

cron-generator

Text & Encoding

Build a cron expression from fields or pick a preset — get the expression plus a human-readable description.

placeholder-image-url

Text & Encoding

Build URLs for placeholder images — picsum.photos, placeholder.com, dummyimage.com and ui-avatars — with the matching HTML/Markdown/BBCode snippets.

fake-data-generator

Text & Encoding

Generate realistic-looking fake people data — names, emails, phones, addresses — for seeding databases, designing UIs and writing tests.

json-diff

Text & Encoding

Compare two JSON documents and show added, removed and changed fields as a path-based tree.

json-merge

Text & Encoding

Deep-merge two JSON documents — choose how to handle conflicting keys and arrays.

json-patch-generator

Text & Encoding

Generate an RFC 6902 JSON Patch describing the changes needed to turn one JSON document into another.

json-patch-apply

Text & Encoding

Apply an RFC 6902 JSON Patch to a JSON document — supports add, remove, replace, move, copy and test.

json-schema-generator

Text & Encoding

Infer a JSON Schema (Draft-07) from any JSON document — nested objects and array element types are inferred recursively.

json-flatten

Text & Encoding

Flatten a nested JSON document to a single-level object with dot, underscore or bracket paths.

json-unflatten

Text & Encoding

Expand a flat dot/bracket-keyed object back into nested JSON — numeric keys become array indices.

json-sort-keys

Text & Encoding

Sort the keys of a JSON object alphabetically — recursively, case-insensitively, or with numeric awareness.

json-path-finder

Text & Encoding

Query a JSON document with a JSONPath expression — supports $, ., [n], [*], ..key and [?(@.field op value)] filters.

json-to-go-struct

Text & Encoding

Generate Go structs with json tags from any JSON payload — nested objects become separate named types.

json-to-python-class

Text & Encoding

Generate Python @dataclass, pydantic BaseModel or TypedDict definitions from any JSON payload.

json-to-rust-struct

Text & Encoding

Generate Rust structs with serde derives from any JSON payload — fields auto-renamed to snake_case.

json-to-csharp-class

Text & Encoding

Generate C# classes from JSON with typed properties for nested objects and arrays.

json-to-kotlin-data-class

Text & Encoding

Generate Kotlin data classes from JSON for Android, Ktor and API clients.

word-counter

Text & Encoding

Count the words in any text — plus characters, lines, paragraphs and estimated reading time. Free, online, no signup.

character-counter

Text & Encoding

Count characters in any text — with and without spaces — plus words, lines and paragraphs. Free, online, runs in your browser.

text-diff

Text & Encoding

Compare two texts side by side and highlight added, removed and unchanged lines, words or characters.

markdown-table-builder

Text & Encoding

Paste tab-separated values and get a clean GitHub-flavored Markdown table — instantly.

nato-phonetic-alphabet

Text & Encoding

Convert text to NATO phonetic alphabet (Alpha, Bravo, Charlie…) and back — free, in your browser.

ip-address-lookup

Text & Encoding

Analyze an IP address — validate format, identify type (private/public/loopback), class, and binary representation.

email-validator

Text & Encoding

Validate email addresses instantly — check format, detect typos, spot disposable providers. Free online tool, no signup.

markdown-to-slack

Text & Encoding

Convert standard Markdown to Slack mrkdwn format — bold, italic, links, code blocks, lists. Free, instant, in-browser.

crc32-checksum

Text & Encoding

Calculate the CRC32 checksum of any text — hex and decimal output. Free, instant, runs in your browser.

html-to-text

Text & Encoding

Strip HTML tags and convert to clean plain text — handles entities, scripts, styles, links. Free, instant, in-browser.

text-to-ascii-art

Text & Encoding

Convert text to ASCII art block letters — A-Z, 0-9, punctuation. Free, instant, in-browser.

utm-url-builder

Text & Encoding

Build campaign URLs with UTM source, medium, campaign, term and content parameters.

url-parser

Dev

Break a URL into its components — protocol, host, port, path, query parameters, hash — with each query param listed individually.

user-agent-parser

Dev

Parse a browser User-Agent string into structured browser/engine/OS/device fields.

http-status-code

Dev

Look up any HTTP status code — title, category, RFC explanation, and the situations it's actually used for.

mime-type-lookup

Dev

Look up the MIME type for a file extension, or the canonical extensions for a MIME type — covering 100+ common types.

subnet-calculator

Dev

Calculate network/broadcast addresses, host range, mask, wildcard mask, host counts, and IP class from a CIDR.

css-minifier

Dev

Minify CSS — strip whitespace, comments and unused syntax to ship smaller stylesheets.

css-beautifier

Dev

Pretty-print CSS — choose 2-space, 4-space or tab indentation for readable stylesheets.

html-minifier

Dev

Minify HTML — collapse whitespace, drop comments and optionally compress inline JS and CSS.

html-beautifier

Dev

Pretty-print HTML — readable indentation with nested tags on their own lines.

js-minifier

Dev

Minify JavaScript with Terser — compress, mangle and ship the smallest possible bundle.

js-beautifier

Dev

Pretty-print JavaScript — consistent indentation and one statement per line for readable code.

sql-formatter

Dev

Format SQL queries for every major dialect — Postgres, MySQL, SQLite, BigQuery, Snowflake and more.

xml-formatter

Dev

Pretty-print XML documents — indent nested tags with 2 or 4 spaces for readable markup.

yaml-formatter

Dev

Reformat YAML — normalize indentation, line wrapping and quoting for tidy config files.

csv-validator

Dev

Validate CSV data — check column consistency, count rows and surface parse errors.

px-to-rem

Dev

Convert between px, rem and em based on a root font size — instant CSS-ready values, in-browser.

type-scale-generator

Dev

Build a modular typographic scale from a base size and ratio — px, rem and CSS variables, in-browser.

line-height-calculator

Dev

Resolve any CSS line-height (unitless, px or %) to its computed pixel height and ratio — in-browser.

svg-minifier

Dev

Minify SVG markup — strip comments, declarations and whitespace to shrink file size, all in your browser.

htaccess-to-nginx

Dev

Convert Apache .htaccess rewrite rules and directives to nginx configuration — free, in your browser.

regex-cheat-sheet

Dev

Interactive regex reference — anchors, quantifiers, groups, character classes, lookaround, and flags with examples.

json-validator

Dev

Validate JSON and see errors with line numbers — plus auto-format/beautify. Free, instant, in-browser.

chmod-calculator

Dev

Convert between numeric (755) and symbolic (rwxr-xr-x) Unix file permissions. Free, instant, in-browser.

meta-tag-generator

Dev

Generate HTML meta tags for SEO, Open Graph, and Twitter Cards. Free, instant, copy-paste ready.

csp-header-builder

Dev

Build a Content-Security-Policy header interactively — select policies for each directive and get the full header string.

robots-txt-tester

Dev

Test whether a URL path is allowed or blocked by robots.txt rules for a specific crawler.

hreflang-tag-generator

Dev

Generate hreflang alternate link tags from language codes and localized URLs.

instagram-id-finder

Dev

Find the numeric Instagram user ID for a public profile URL or username.

facebook-id-finder

Dev

Find the numeric Facebook profile or page ID from a public URL, username, or ID link.

luhn-check

Payment & cards

Validate a card number with the Luhn (mod-10) algorithm — runs locally in your browser.

card-number-generator

Payment & cards

Generate Luhn-valid test card numbers (Visa, Mastercard, Amex, Discover, JCB, Diners) — for development only.

card-brand-identifier

Payment & cards

Identify the card scheme (Visa, Mastercard, Amex, Discover, JCB, Diners, UnionPay) from a PAN.

bin-lookup

Payment & cards

Look up a card BIN (Bank Identification Number) to identify scheme, issuer, country and type.

emv-tlv-decoder

Payment & cards

Decode EMV / ISO 7816 BER-TLV hex into a labelled tree of tags, lengths and values.

emv-tag-lookup

Payment & cards

Search the EMV / ISO 7816 tag dictionary by hex tag or by name fragment.

track1-decoder

Payment & cards

Decode an ISO 7813 Track 1 magstripe string into PAN, cardholder name, expiry and service code.

track2-decoder

Payment & cards

Decode an ISO 7813 Track 2 magstripe string into PAN, expiry, service code and discretionary data.

pin-block

Payment & cards

Generate an ISO 9564 PIN block (formats 0, 1 and 3) from a PIN and PAN — runs locally in your browser.

kcv-calculator

Payment & cards

Compute the Key Check Value (KCV) of a single, double or triple length DES key by encrypting 8 bytes of zeros.

iso4217-currency

Payment & cards

Look up a currency by ISO 4217 code (alpha or numeric) or by name fragment.

iso3166-country

Payment & cards

Look up a country by ISO 3166-1 alpha-2, alpha-3, numeric code, or by name fragment.

mcc-lookup

Payment & cards

Look up an ISO 18245 Merchant Category Code by 4-digit code or by name fragment.

iban-validator

Payment & cards

Validate an IBAN — checks the country format, length and ISO 13616 MOD-97 checksum.

swift-bic-validator

Payment & cards

Validate a SWIFT/BIC code format and break it down into bank, country, location and branch fields.

iso639-language-lookup

Payment & cards

Look up a language by ISO 639-1 alpha-2, ISO 639-2/3 alpha-3, or by name fragment.

card-pan-formatter

Payment & cards

Format a card number for display — brand-aware grouping plus a masked version safe to show in receipts.

dukpt-pin-block-calculator

Payment & cards

Compute the ISO 8583 field 52 encrypted PIN block from a PIN, PAN, BDK and KSN — full TDES DUKPT key derivation.

Frequently asked

Do my tokens, keys and payloads get uploaded anywhere?

No. The paste-and-transform text utilities — encoding, decoding, hashing, HMAC, JSON formatting, regex testing — run entirely in your browser as JavaScript or WebAssembly, so no request fires and the input never leaves the tab. You can verify it directly: open DevTools, switch to the Network panel, and run a transform — the request list stays empty while the output updates. A few file-output tools do heavier work and are labeled as such.

What's the difference between decoding a JWT and verifying it?

Decoding just Base64url-decodes the header and payload so you can read the claims — anyone can do this, because a JWT's payload is encoded, not encrypted. Verifying recomputes the signature using the issuer's secret (HS256) or public key (RS256) and confirms the token wasn't tampered with. The decoder here reads claims; always verify the signature server-side before trusting any claim, and never put secrets in the payload.

Is Base64 a form of encryption?

No — it's encoding, fully reversible by anyone with no key. Base64 exists to represent binary data safely as text (for data URIs, email attachments, token segments), not to hide it. If you need confidentiality, use encryption; if you need a one-way fingerprint for integrity or password storage, use a hash like SHA-256 or bcrypt.

When should I use HMAC versus a plain hash?

Use a plain hash (SHA-256, or MD5 for legacy checksums) when you just need a fingerprint of public data — file integrity, content addressing. Use HMAC when you need to prove the data came from someone holding a shared secret, such as signing a webhook body or an API request so the receiver can confirm it wasn't forged. HMAC is a keyed hash; a plain hash has no key and anyone can recompute it.

Why is bcrypt slow, and is that a bug?

It's the whole point. bcrypt has a tunable work factor (cost) that makes each hash deliberately expensive to compute, so an attacker who steals your password database can only test a few thousand guesses per second instead of billions. Raise the cost as hardware gets faster. To verify a password you don't recompute and compare strings — you feed the candidate and the stored hash to bcrypt's verify, which extracts the embedded salt and cost automatically.

Can I decode EMV chip data and other payment fields here?

Yes — this site carries payment-data utilities that are genuinely hard to find elsewhere: an EMV TLV decoder that parses tag-length-value chip data into named EMV tags, plus EMV tag lookup, BIN and MCC lookups, IBAN and SWIFT/BIC validation, Luhn (mod-10) checks and card-brand identification. They run in the browser like the rest of the toolbox.

Do these tools work offline?

Largely, yes. Because the text transforms execute client-side, once a tool's page has loaded you can keep encoding, hashing, formatting and testing regex with no network connection. There's no server round-trip and no session, which is also why there's nothing to sign up for.

Should I use a UUID or a ULID for my IDs?

Use a UUID v4 when you want a purely random, collision-resistant identifier and ordering doesn't matter. Reach for a ULID when you want IDs that sort lexicographically by creation time — they embed a millisecond timestamp prefix, which makes them friendlier for database indexes and cursor pagination. The UUID generator covers the random case; the field guide walks through the trade-off.