Skip to main content
WizTools123
WizTools123
Free Online Tools

Tool Categories


Security Tools 504 Tools Available

Free Online Hash, Encryption, Certificate, JWT & Password Hash Tools

Do the exact small jobs security work is made of, without the input ever leaving the tab. Hash text or a file and compare it, work out an HMAC, identify a hash you were handed, hash a password with PBKDF2 or bcrypt, encrypt with AES, generate an RSA key pair, read a certificate or a CSR, sign and verify a JWT, and escape text so it cannot break out.

Nothing Uploaded, Ever No Keys Stored The Browser Own Crypto Limits Stated Plainly Works on a Phone
Free Online Hash, Encryption, Certificate, JWT & Password Hash Tools
Share this tool
Advertisement Slot (Top Banner) Google AdSense Unit • Responsive Banner

Choose a Security Tool

Grouped by what you are trying to do. Find the sentence that sounds like you.

Buy Us A Coffee

Enjoying WizTools123? Help keep our server infrastructure 100% free and open for everyone.

Buy Us A Coffee
Sponsored Content (Below Tool) Google AdSense Placement

Which Tool Do I Need?

Find the sentence that sounds like you.

Work out or check a hash

Something gave you a long string of hex and you need to produce it, match it, or find out what it even is.

What you are trying to do Tool Why that one
I need a checksum, or the MD5 of some text Hash Generator MD5 through SHA-512 at once, from text or a file, with a compare box.
My webhook signature does not match and I cannot see why HMAC Generator Reads the key as text, hex or base64 and shows both output forms, which is where the mismatch usually hides.
I have a hash from a database and I do not know what made it Hash Identifier Reads the prefix where there is one, and lists every candidate where there is not.

Store a password safely

You are putting passwords in a database and the plain text must never be one of the things you keep.

What you are trying to do Tool Why that one
I need a bcrypt hash, or to check a password against one Password Hash Generator Hashes with bcrypt or PBKDF2, verifies an existing hash, and times the work factor.
I need a Basic authorization header for a request Basic Auth Generator Builds it and reads it back, and is honest that base64 is not encryption.

Encrypt or decrypt something

A file or a piece of text has to travel, and whoever carries it should not be able to read it.

What you are trying to do Tool Why that one
I need to encrypt a piece of text with a passphrase AES Encrypt and Decrypt Derives the key properly with PBKDF2 and keeps the salt and IV with the ciphertext.
I need an RSA key pair to test something with RSA Key Pair Generator Generates one in the tab and exports it in every shape you are likely to be asked for.
I need to encrypt a short message with somebody public key RSA Encrypt and Decrypt Does OAEP and signatures with a pasted PEM, and tells you the size limit first.

Read a certificate, a key or a token

Someone sent you a block of base64 beginning with five dashes, or a token in three parts, and you need to see inside it.

What you are trying to do Tool Why that one
Someone sent me a token in three parts and I need to see inside it JWT Encoder and Decoder Decodes the claims, checks the signature, and signs a test token.
I need to see what is inside this certificate Certificate Decoder Decodes it in the tab, dates and names and extensions, with the ASN.1 tree underneath.

Escape text so it cannot break out

Text written by somebody else is about to land inside HTML, a script or an XML document, and it must stay data.

What you are trying to do Tool Why that one
This text has to go inside HTML, a script or an XML file without breaking it Escape and Unescape Tool Escapes by the rules of the language you name, and unescapes from a table rather than the HTML parser.

How These Security Tools Work

The same four steps, whichever one you pick.

1
Open the tool for the job They are grouped above by what you are trying to do, because the name of the thing you need is often the part you do not know yet.
2
Paste the input, or pick a file Everything happens in the page. Most tools update as you type, and the ones that cannot, such as key generation, say what they are doing while they do it.
3
Read what it did, not just the result Every page says which algorithm ran, which parameters were used, and where the output is only as good as the input. A hash with no salt and a hash with one look identical; what they mean does not.
4
Copy it, and close the tab Nothing you typed is kept. Closing the tab is the whole of the cleanup, because there is nothing in storage to clear.

Why These Rather Than the Usual Dev Tool Sites

The things that are actually different, not a list of adjectives.

A secret that reaches a server is no longer a secret This is the one category where uploading the input defeats the purpose entirely. A private key, a passphrase or a token pasted into a web form has been shared with whoever runs that form. Everything here runs in your own browser, which you can confirm in the Network tab or by working with the network switched off.
Nothing is remembered Other hubs on this site save your setups and your history so you can come back to them. These tools deliberately do not. A passphrase or a private key left in browser storage is exactly the kind of thing that gets found later, so there is no storage to find.
The browser own cryptography, not a reimplementation AES, RSA, HMAC, SHA-2 and PBKDF2 all run through Web Crypto, the same vetted code your browser uses for HTTPS. Hand written cryptography is where quiet, serious mistakes live, so the only things written by hand here are the parsers and the one old algorithm the browser refuses to provide.
Honest about what is broken MD5 and SHA-1 are still here because real systems still use them, and every page that offers them says plainly that they are broken for anything security related. A tool that hands you a weak answer without saying so is worse than no tool.
The parameters are yours Iteration counts, key sizes, salt lengths, cipher modes and cost factors are all on the page rather than hidden behind a sensible default. The defaults are sensible, and they are also visible and changeable, because the parameter is usually the whole answer to whether the output is any good.
They tell you where they stop The certificate decoder reads a certificate but cannot tell you whether it is trusted. The JWT tool verifies a signature but cannot know whether the key is the right one. Each page says where its knowledge ends instead of implying it goes further.

About WizTools Security Tools

Security work involves a long tail of small, exact jobs. Hash this file and compare it with the one the vendor published. Read the certificate somebody emailed and find out when it expires. Sign a token so a test will accept it. Turn a passphrase into a key and encrypt one file. None of these is difficult, and all of them are the kind of thing people reach for a web tool to do, which is where the problem starts: the input is usually the secret, and most web tools send it to a server.

Everything in this category runs in the page. Where the browser provides the algorithm, the browser does the work: AES, RSA, HMAC, the SHA-2 family and PBKDF2 all come from Web Crypto, which is the same implementation the browser uses for HTTPS and has been examined far more carefully than anything written for a tools site could be. Where the browser does not provide something, it is written here and said so, which is true of MD5, of bcrypt, and of the DER parser behind the certificate decoder.

The hardest part of building these was deciding what not to do. There is no Argon2, because the only way to run it in a browser is a WebAssembly bundle that takes a second or two on a phone and would still be the wrong answer, since a password hash should be computed where the password arrives and not in a browser tab. Nothing saves your input, so none of these pages has the saved setups and history that the rest of the site has. And no page claims to validate trust: a certificate decoder can tell you what a certificate says, and only a browser with a root store can tell you whether to believe it.

What every page does carry is the parameters and the caveats. The iteration count, the key size, the cipher mode, the salt, the cost factor: all visible, all editable, and all explained where the choice actually matters. That is the part a tool can genuinely help with, because the arithmetic was never the hard bit. Knowing that the same password with the same salt and a hundred times fewer iterations produces an answer that looks exactly as convincing and is worth far less, that is the bit worth putting on the screen.

Frequently Asked Questions

About the set as a whole. Each tool has its own answers too.

No. Every tool in this category works entirely in your browser: open the Network tab and the page loads its own code and then makes no further requests. You can switch the network off after the page has loaded and everything still works, which is the easiest way to prove it to yourself.

The code never sends them anywhere, so the risk is not this site. It is the machine and the browser you are sitting at: an extension, a shared computer or a screen recorder sees what is on the page whatever the page does. For a production private key, generating it on the server that will use it is still the right habit.

Because real systems still use it, and a checksum from a download page is often an MD5. Broken means two different inputs can be made to produce the same hash, which ruins it for signatures and for passwords. It is still useful for spotting accidental corruption, and every page that offers it says exactly that.

Deliberately. The rest of this site saves setups and history in your browser so you can come back to them, and in this category that would mean a passphrase or a private key sitting in browser storage waiting to be found. There is no storage here to clear, which is why closing the tab is the whole of the cleanup.

No, and that is a decision rather than an omission. Argon2 in a browser needs a WebAssembly bundle that is slow on a phone, and a password hash should be computed where the password arrives, which is your server. The password hash page offers PBKDF2 and bcrypt and explains where Argon2 belongs instead.

They can tell you what it says: who it was issued to, by whom, when it expires, which names it covers and what its fingerprint is. Whether to trust it is a different question that needs a root store and a revocation check, and no page here pretends to answer it.

Yes, once the page has loaded. The algorithms come from your browser and from the page itself, so there is nothing to fetch. The only tools that would need a network are the ones that would have to reach another site, and there are none of those in this category.

Every Other Category

20 more sets of tools on the site. All free, all in your browser.

Advertisement Slot (Bottom Banner) Google AdSense Unit • Responsive Banner