Security Utilities
Tokens, certificates, HTTP headers, and credential validation.
Security Tools
Tokens, certificates, HTTP headers, and credential validation.Decode JWT header, payload and signature locally.
Score passwords and see how to improve them.
Decode X.509 certificates (PEM format) locally: inspect issuer, validity dates, and serial.
Validate test card numbers using the Luhn checksum algorithm and detect card network locally.
Analyze and troubleshoot Cross-Origin Resource Sharing (CORS) preflight and response headers.
Audit web response security headers: HSTS, CSP, X-Frame-Options, and Referrer-Policy.
Generate otpauth:// QR codes for Google Authenticator, Authy, and 1Password.
Decode PKCS#10 Certificate Signing Requests into Subject, Public Key, and domain fields.
Create and cryptographically sign HMAC-SHA256 (HS256) JSON Web Tokens client-side.
Generate cryptographically random API keys and secrets with custom prefixes.
Why use Security utilities on debug.tools?
Every tool in this category executes entirely within your browser runtime using the Web Crypto API, Canvas API, or native JavaScript parsers. Whether you are working with proprietary enterprise data, sensitive keys, or private files, your inputs are never transmitted over the internet or logged to any server.
Frequently Asked Questions
Are the utilities in Security free to use?
Yes, all tools in the Security category are 100% free with no account creation, subscriptions, or rate limits.
Do tools in Security upload my files or data to a server?
No. Every calculation, format conversion, and media transformation executes strictly inside your local browser memory using client-side JavaScript and modern Web APIs.
Can I use these Security tools offline?
Yes. Once the page is loaded in your browser, the tools operate with zero remote API dependencies and work completely offline.