Read a JWT or make a throwaway password

Look at a token, make a charset password, or lock a string with a key you already have. Readable is not trusted.

Login failed and the access token looks expired. A form wants a 16-character password. A note must not travel as plaintext. Security pages here stay local. They do not replace an IdP, Bitwarden, or a lawyer.

Read the warning on each door

  • JWT decoder splits header and payload. Not signature verify. JWT is not encryption. Treat alg:none as hostile.
  • Password generator is crypto.getRandomValues over a charset. Store the result in a manager; this page will not remember it.
  • AES encrypt / decrypt is for text plus a passphrase you manage. Losing the key loses the plaintext. Not a file-vault product.
  • HMAC / password check is a developer MAC helper, not “is this password in Have I Been Pwned.”

PDF “sign” and “protect” are file stamps and passwords — not eIDAS or DocuSign. QR payment codes are out of scope.

Decode, encrypt, stamp — different promises

JWT: decode header/payload, no signature verify, warn alg:none. AES: lab round-trip, not a vault. PDF protect is an open password in this tab. Sign-PDF is a drawn stamp, not eIDAS. Paycheck tax % is not a withholding engine.