Look at a token, make a charset password, or lock a string with a key you already have. Readable is not trusted.
Login failed and the access token looks expired. A form wants a 16-character password. A note must not travel as plaintext. Security pages here stay local. They do not replace an IdP, Bitwarden, or a lawyer.
Read the warning on each door
- JWT decoder splits header and payload. Not signature verify. JWT is not encryption. Treat
alg:noneas hostile. - Password generator is
crypto.getRandomValuesover a charset. Store the result in a manager; this page will not remember it. - AES encrypt / decrypt is for text plus a passphrase you manage. Losing the key loses the plaintext. Not a file-vault product.
- HMAC / password check is a developer MAC helper, not “is this password in Have I Been Pwned.”
PDF “sign” and “protect” are file stamps and passwords — not eIDAS or DocuSign. QR payment codes are out of scope.
Decode, encrypt, stamp — different promises
JWT: decode header/payload, no signature verify, warn alg:none. AES: lab round-trip, not a vault. PDF protect is an open password in this tab. Sign-PDF is a drawn stamp, not eIDAS. Paycheck tax % is not a withholding engine.