Encoding & Hashing Tools

Base64, URL and HTML escaping, hex, ROT13, four hash functions and a JWT decoder — all running in your browser, with nothing sent to a server. Each one also tells you what it is not good for, which is where most of the damage gets done.

Key takeaway: encoding, hashing and encryption are three different things that get used interchangeably, usually by someone about to make a mistake. Encoding is reversible by design and protects nothing. Hashing is one-way and proves integrity, not secrecy. Encryption is the only one of the three that keeps a secret, and none of these tools does it.

Encoding is not encryption

Base64 exists so that arbitrary data survives systems that expect plain text — email attachments, data URLs, JSON fields. It uses no key and hides nothing. Anyone who sees cGFzc3dvcmQxMjM= can paste it into the box above and read it, and every attacker’s toolkit decodes it automatically.

This matters because Base64 looks scrambled, and things that look scrambled get treated as safe. Credentials get Base64-encoded into config files and headers on the assumption that it counts as protection. It does not. HTTP Basic Authentication sends your password as Base64 for exactly this reason — it is encoding for transport, and the security comes entirely from the TLS layer underneath.

Which hash to use, and which to stop using

A hash turns any input into a fixed-length fingerprint. The same input always gives the same output, and you cannot work backwards from the output. That makes hashes useful for verifying a file arrived intact, for spotting duplicates, and for signatures.

Two of the four here are broken for anything security-related, and the tool labels them:

HashStatus
MD5Broken. Two different inputs with the same hash can be produced in seconds on a laptop. Still fine as a checksum against accidental corruption, and widely used that way. Never for anything an attacker would want to forge.
SHA-1Broken. A real collision was demonstrated in 2017, and chosen-prefix attacks followed in 2020. Certificate authorities and browsers dropped it years ago. Git still uses it for object naming, which is integrity, not security.
SHA-256Current standard. What TLS certificates, signatures and blockchains rely on.
SHA-512Same family, longer output. On 64-bit hardware it is often faster than SHA-256.

“Broken” has a specific meaning: it is still infeasible to take a given MD5 hash and find the original input. What has fallen is collision resistance — the ability to produce two different files with the same fingerprint. That is what matters when a hash is used to prove a document has not been swapped.

Never hash a password with these

This is the mistake these tools get used for most. SHA-256 is designed to be fast, and fast is precisely wrong for passwords — an attacker with a stolen database and a GPU makes billions of guesses a second. Password storage needs a deliberately slow algorithm built for the job: bcrypt, scrypt or Argon2, each of which is tunable so verification stays quick for one login while bulk guessing stays expensive.

If you are checking your own passwords rather than storing other people’s, the password tools will tell you how strong one is and whether it has appeared in a breach.

The JWT decoder decodes. It does not verify.

A JSON Web Token has three parts: a header, a payload of claims, and a signature. The first two are just Base64 — readable by anyone, which is why you should never put anything private in a token payload.

The signature is the part that makes a token mean something, and checking it requires the issuer’s secret or public key. This page does not have that key and should never be given it, so it decodes and stops. A token that decodes cleanly and shows plausible claims is not evidence of anything — anyone can produce a token that says they are an administrator. Only signature verification, done server-side, turns a claim into a fact.

What the decoder is genuinely good for: reading the expiry, checking which issuer a token came from, and seeing what claims an application is actually sending while you debug it.

URL and HTML escaping

These two exist because text gets embedded inside other languages, and characters that are ordinary in one are structural in another.

URL encoding replaces characters that would otherwise break a URL — a space becomes %20, an ampersand in a value becomes %26 so it is not read as a separator. Note the distinction browsers make: encodeURIComponent, used here, escapes everything unsafe in a value, while encodeURI leaves the structural characters of a full URL alone. Using the wrong one is a common source of broken query strings.

HTML escaping turns < into &lt; so the browser displays it instead of treating it as a tag. This is the mechanism behind preventing cross-site scripting, though escaping on output in your templating layer — not in a text box — is how it should be done in practice.

Encoding protects nothing in transit

None of these transformations hides anything from someone watching the connection. On an untrusted network, what actually protects your traffic is TLS, and a VPN on top of it for the parts TLS leaves visible — which sites you contacted, and when. That metadata is available to your provider and to whoever runs the network you are using.

PureVPN How traffic gets captured

Affiliate link. We do not rank by commission — compare providers yourself.

What these tools cannot do

Reverse a hash. Sites offering to “decrypt MD5” are looking the hash up in a table of pre-computed common inputs. That works for password and fails for anything unpredictable — the hash itself is not reversible.

Keep a secret. Base64, hex and ROT13 are all trivially reversible, by design.

Validate a token. See the JWT section — decoding is not verification.

Handle files. These work on text you paste. For checksumming a downloaded file, use certutil -hashfile file SHA256 on Windows or shasum -a 256 file on macOS and Linux, which reads the bytes on disk rather than a copy pasted through a browser.

Frequently asked questions

Is my input sent anywhere?

No. Every function here runs in JavaScript in your browser — hashing uses the browser’s built-in Web Crypto API. You can disconnect from the internet and the page keeps working, which is the easiest way to confirm it.

Why do two tools give different hashes for the same text?

Almost always a trailing newline, or a different character encoding. A text box that adds a line break at the end produces a completely different hash. This tool hashes exactly the bytes you supply, as UTF-8.

Can I use Base64 to hide an API key in my code?

No, and it is worth being blunt about it: anything shipped to a browser or an app is readable by whoever has it. Encoding adds a few seconds of inconvenience. Keys that must stay secret belong on a server.

What is ROT13 for?

Hiding spoilers and puzzle answers from casual reading. It has no security value whatsoever — it is its own inverse, so applying it twice returns the original text.

Which hash should I use for file integrity?

SHA-256. If a project publishes MD5 checksums, they still catch accidental corruption, which is usually what you are checking for — but they do not prove nobody tampered with the file.

Related reading

Other tools

Scroll to Top