Security

Password generation, hashing, one-time passwords and HTTP security headers.

Anything that needs randomness uses the browser's cryptographic random source (crypto.getRandomValues from the Web Crypto API) rather than the predictable Math.random. Hashing and signing are likewise delegated to the Web Crypto API, using the browser's own standard implementation. Where a tool implements a published specification, it has been checked against the official test vectors in that spec: RFC 6238 for TOTP, RFC 4226 for HOTP, RFC 7617 for Basic authentication headers, RFC 4122 for UUID v5 and RFC 4648 for Base32. There are also builders for HTTP security headers including CSP, HSTS and Referrer-Policy.

What people use these for

  • Generate a strong password or PIN on the spot
  • Compute a file's SHA-256 hash to compare against a published checksum
  • Set up a TOTP secret and QR code for an authenticator app
  • Assemble a correctly formatted CSP or HSTS header

Tools in this category (31)

Browse other categories