🔐Free Crypto & Security Tools Online
Security utilities that run in your browser: hash text with bcrypt and SHA, generate RSA key pairs, encrypt with AES, and set up 2FA authenticator codes. No signup, your input stays on your device.
5 free crypto & security tools below — pick one to get started.
Bcrypt Generator & Verifier
Passwords should not be stored as plain text or protected only with a fast general-purpose digest such as MD5 or SHA-256. This browser-based bcrypt generator and verifier helps developers create salted bcrypt hashes and test candidate-password matches for development and interoperability checks. Bcrypt uses a per-hash random salt and an adjustable work factor to make each offline password guess more computationally expensive. Hashing and verification occur locally in the browser using bcryptjs, and the tool does not intentionally send entered values to our servers. For production authentication, use a maintained server-side password-hashing library and benchmark the work factor on the target infrastructure. For new systems, evaluate Argon2id where supported.
RSA Key Pair Generator
This tool generates an RSA signing key pair (RSASSA-PKCS1-v1_5 with SHA-256) locally in your browser using the Web Crypto API. The public key is exported as SPKI PEM and the private key as unencrypted PKCS#8 PEM, formats accepted by many cryptographic libraries and OpenSSL-based workflows. Because this is a signing key pair, it is suitable for RS256-compatible JWT signing workflows — not for RSA encryption. The tool does not intentionally send generated key material to our servers. The downloaded private key is not passphrase-protected, so protect it immediately. Best suited to testing and controlled workflows; production keys belong in an approved key-management system or hardware security module.
AES Encryption & Decryption
Sensitive notes and configuration values should not be stored or shared as plain text. This browser-based AES encryption and decryption tool uses the Web Crypto API to encrypt text and create a portable ciphertext envelope containing the parameters required for decryption. AES-GCM is the recommended default because it provides both confidentiality and integrity verification, while AES-CBC should be used only for compatibility with systems that provide a separate authentication mechanism. Cryptographic operations are performed locally, and the tool does not intentionally send the entered plaintext or passphrase to our servers. This utility is intended for testing and controlled workflows and does not replace HTTPS, secure key exchange, or an approved secret-management system.
HMAC Generator
Web APIs, microservices, and webhook integrations commonly use Hash-based Message Authentication Codes (HMACs) to detect payload changes and verify that a signature was generated by a party possessing a shared secret. This browser-based HMAC generator calculates message authentication codes with HMAC-SHA-256, HMAC-SHA-384, HMAC-SHA-512, and legacy HMAC-SHA-1. It is useful for creating test vectors and debugging signature mismatches when you know the exact message bytes, key encoding, algorithm, and output format. Calculations run locally through the browser's Web Crypto API, and the tool does not intentionally send entered secrets or payloads to our servers. HMAC does not encrypt data or prevent replay attacks by itself.
TOTP Authenticator Generator
This browser-based TOTP generator computes time-based authentication codes directly on your device using the Web Crypto API. It is designed primarily for developers testing multi-factor authentication flows, validating TOTP configurations, and troubleshooting authorized accounts. Enter a Base32-encoded secret, choose 6 or 8 digits and the HMAC algorithm (SHA-1, SHA-256, or SHA-512), and the tool generates the corresponding rolling code on the commonly adopted 30-second time step — with a live countdown, next-code preview, and a verification module to check codes against the secret. Because a TOTP secret can generate future authentication codes, treat it like a sensitive credential: prefer test secrets, and avoid entering secrets for active production accounts unless necessary.