Developer kit: checksums, Base64, JWT, timestamps
Four small things developers reach for every day, on one page. Files and tokens stay on your device.
🔒 Your files never leave your device
MD5 and SHA-1 are fine for spotting corrupted downloads but are broken for security; use SHA-256 to check a file hasn't been tampered with.
Text is treated as UTF-8, so accents and emoji round-trip correctly. Decoding accepts both standard and URL-safe Base64, with or without padding.
⚠️ Decode only: the signature is NOT verified. Anyone can make a token that decodes to anything, so never trust these claims for security decisions. Avoid pasting live production tokens anywhere you don't trust (this page doesn't send them anywhere).
Current Unix time:
Numbers are read as seconds, milliseconds, microseconds or nanoseconds depending on their size.
How it works
SHA-256, SHA-1 and SHA-512 use your browser's built-in Web Crypto; MD5 uses a small implementation of RFC 1321 included with this page (tested against the official test vectors). Base64, JWT and timestamp conversions are plain JavaScript on your device.
Limits: checksums read the whole file into memory, so very large files (over about 1 GB) aren't supported and big files may take a few seconds. JWTs are decoded, never verified. Timestamps before 1973 in milliseconds may be read as seconds; add digits or use a date string if that happens.
Privacy: the tool runs in your browser, so nothing you add (files, text, passwords) is uploaded or stored by us. No account needed. It also works offline once loaded.