Developer tools for inspecting text, data and representations
These utilities help inspect and transform data in the browser. A successful transformation is not a security certification: valid JSON can be wrong for an API, and a decoded token can still be untrusted.
Choose by the task
- Parse JSON, encode transport text, inspect JWT claims, test JavaScript patterns or generate identifiers.
- Choose the representation before transforming it; successful parsing does not validate meaning or security.
Data and encodings
JSON Formatter & Validator
Format, minify, and validate strict JSON directly in your browser.
JSON ↔ CSV Converter
Convert arrays of JSON objects and correctly quoted CSV data locally.
Base64 Encoder & Decoder
Encode Unicode text to Base64 or decode UTF-8 Base64 text locally.
URL Encoder & Decoder
Encode and decode URL components safely in your browser.
Tokens and identifiers
Time and matching
Keep syntax, encoding and meaning separate
JSON formatting checks parsing, while JSON/CSV conversion changes a data representation with limits around nested values and types. Base64 and URL encoding solve transport problems; neither encrypts text. Know which layer you are working with before decoding repeatedly.
Unix timestamps need a unit and time-zone interpretation. Regex uses JavaScript behavior, which may differ from a backend engine. A local match preview is not a guarantee that the same pattern behaves identically in another language.
Handle secrets as secrets even during debugging
JWT inspection does not verify signatures or authorize requests. SHA digests are not password-storage schemes. UUIDs are identifiers, not a promise of secrecy or access control.
Processing is local, but copying results, sharing screenshots or sending support email can disclose them. Use synthetic examples when reporting an issue. Avoid running pathological regular expressions: bounded input is not a guarantee of a fixed execution time.
Questions about this topic
Does a valid decoded token prove a user’s identity?
No. Decoding only exposes the representation. A trusted application must perform signature verification, claim checks and authorization using its own policy.
