Input safety
Use sample values instead of production tokens, private keys, personal data, or confidential business material.
Development helpers such as JWT, Base64, hashing, and regex tools are best used with non-sensitive examples.
Security guidance for using ToolBada utilities, sharing outputs, and checking browser environments.
Use sample values instead of production tokens, private keys, personal data, or confidential business material.
Development helpers such as JWT, Base64, hashing, and regex tools are best used with non-sensitive examples.
Before sharing copied output or downloaded files, check for personal data, hidden metadata, and formatting requirements.
For public computers or browsers with many extensions, avoid handling sensitive documents.
Every page is served over HTTPS, and a content security policy blocks scripts from origins that are not on the allow list. Code needed to run a tool is limited to files served from this domain.
Tools that perform cryptographic work — hashing, HMAC, token generation — use the Web Crypto API built into the browser rather than hand-rolled randomness or a remote service that would receive your key.
If a tool returns a wrong result or behaves in a way that looks like a security problem, write to [email protected] with the page URL, the shape of the input you used, and what you observed.
Fixes are recorded on the notices page once they ship. Please do not include real credentials or production tokens in a report — substitute a fake value of the same shape.
Review browser compatibility, data handling, security, privacy, and calculation methodology.