Free tools for developers
UUID generators, JSON formatters, JWT decoders and more — fast, free, and 100% private. Every tool runs locally in your browser; your data never touches a server.
Search tools
Search for a developer tool
Popular categories
Encoding
16 toolsThe most-searched category on DevTools Hub — URL encoding, decoding, and Base64 conversions.
Password Security
6 toolsGenerate a strong password, check how one holds up, and set or validate the policy your team follows.
Docker
5 toolsValidate, lint, and visualize Docker Compose files — and make sense of container networking.
Kubernetes
7 toolsValidate manifests, calculate resource requests/limits, and make sense of Kubernetes YAML.
Toolkits
Generators Toolkit
3 toolsIndependent tools for the test data every project eventually needs — unique IDs and placeholder text. All run entirely in your browser.
JSON Toolkit
10 toolsFormat, validate, diff, minify, convert, query, and schema-generate/validate JSON — ten tools for the format everything speaks. All run entirely in your browser.
Encoding Toolkit
16 toolsBase64, URL, HTML, hex, and ASCII encoding and decoding, plus query string and full URL parsing, building, inspection, Unicode analysis, and string-literal escaping — sixteen tools for the encodings that show up constantly in web development. All run entirely in your browser.
Date & Time Toolkit
5 toolsTimestamps, timezones, and cron schedules — five tools for the two date-and-time problems every backend eventually runs into. All run entirely in your browser.
JWT Toolkit
8 toolsEverything for working with JSON Web Tokens, in one place — decode, understand, verify, build, and secure them. All eight tools run entirely in your browser; nothing you paste is ever sent anywhere.
Hashing Toolkit
10 toolsMD5, SHA, checksums, HMAC, and password hashing — ten tools for hashing text, verifying files, and signing messages. All run entirely in your browser.
Regex Toolkit
6 toolsBuild, test, visualize, debug, and escape for JavaScript regular expressions — six tools covering the whole regex workflow. All run entirely in your browser.
SQL Toolkit
6 toolsFormat, validate, minify, diff, index-advise, and explain SQL — six tools covering readability, correctness, schema changes, and performance. All run entirely in your browser.
OpenAPI Toolkit
5 toolsView, validate, diff, and put an OpenAPI/Swagger document to work — five tools covering the full spec lifecycle. All run entirely in your browser.
Docker Toolkit
5 toolsValidate, lint, format, and visualize Docker Compose files and Dockerfiles — five tools covering the whole Docker workflow. All run entirely in your browser.
GitHub Actions Toolkit
4 toolsValidate, visualize, lint, and audit secrets in GitHub Actions workflows — four tools covering correctness and security. All run entirely in your browser.
Environment Toolkit
4 toolsValidate, diff, and convert .env files — four tools for the dotenv format's real parsing rules and the gotchas that fail silently. All run entirely in your browser.
Kubernetes Toolkit
7 toolsValidate, format, calculate resources, diff, explore relationships, and merge or compare Helm values for Kubernetes manifests — seven tools covering correctness, readability, and resource planning. All run entirely in your browser.
YAML Toolkit
2 toolsValidate and format YAML — syntax errors, duplicate keys, parser-version gotchas, and consistent indentation — schema-agnostic, for any YAML file. All run entirely in your browser.
AWS Toolkit
9 toolsParse and build ARNs, generate, review, simulate, and minify IAM policies, validate tag policies, look up Regions, and validate CloudFormation templates — nine tools for everyday AWS work. All run entirely in your browser.
GraphQL Toolkit
2 toolsFormat and validate GraphQL queries, mutations, and SDL schemas with the real reference parser. All run entirely in your browser.
Algorithms Toolkit
8 toolsComputer science fundamentals for practicing engineers — algorithm complexity, performance analysis, and scalability, with interactive tools and practical examples. All run entirely in your browser.
Data Structures Toolkit
4 toolsHow the structures underneath every algorithm actually work — arrays, hash tables, trees, and more, visualized step by step. All run entirely in your browser.
Scalability Toolkit
3 toolsThe numbers behind systems that hold up under load — caching, capacity, and the metrics worth actually tracking. All run entirely in your browser.
Distributed Systems Toolkit
2 toolsTools for the problems that show up once a system spans more than one machine — unique IDs, coordination, and consistency. All run entirely in your browser.
Password Security Toolkit
6 toolsGenerate a strong password, check the strength of one you already have or estimate one hypothetically, define or validate the policy an organization follows, and grade its storage practices. All run entirely in your browser.
Latest tools
Hash Comparison
Compare bcrypt, Argon2, scrypt, PBKDF2, and SHA-256 on speed, security, and memory hardness.
Bcrypt Capacity Planner
Estimate the aggregate CPU impact of a bcrypt cost factor across your users and daily logins.
Password Cracking Time Estimator
Estimate brute-force complexity from a length and character set — no real password needed.
Password Storage Checker
Answer a few questions about your storage practices and get them graded against OWASP/NIST.
Password Policy Validator
Paste a password policy's text and check it against NIST SP 800-63B guidance.
Password Policy Generator
Generate a password policy document and check it against NIST SP 800-63B guidance.
Latest articles
View all postsHow to Validate a CloudFormation Template
"Validate the template" means three different checks — syntax, structure, and resource-property semantics — and a template can pass the first two and still fail on deploy. The real tools for each layer (aws cloudformation validate-template vs. cfn-lint), what Capabilities actually tells you, and why only a change set catches account-specific failures.
Password Security: A Comprehensive Guide
Password security is four separate layers — creating one, the policy an organization sets, how it's actually stored, and defense beyond the password itself — each with its own failure mode. A roadmap connecting all four, linking out to a full deep-dive and the right tool wherever one already exists.
Password Hash Migration Strategies
You can't recompute a stronger hash for a password you don't have — every migration strategy is a different answer to what to do with the one moment you get the real plaintext back. Rehash-on-login, wrap-then-migrate, dual verification during the transition, forced reset, and migrating to a whole new identity provider, mapped to which situation actually needs which one.