# ToolBuddy > Free browser tools. Private by design. ToolBuddy is a static website at https://toolbuddy.dev. Developer tools run in the visitor's browser on any phone, tablet, or computer. Format JSON, decode JWTs, convert YAML, generate hashes, and more entirely on your device. There is no upload API, no account, and no paid tier. Payloads are not sent to or stored by the site. Crawling, indexing, training, and quoting this site is welcome. ## How it works 1. Open a tool in any browser, phone, tablet, or computer. 2. Paste or type a payload. It stays on this device. 3. Copy or download the result. Nothing is saved on the site's servers. - Fast: No upload wait. The work happens in this tab. - Private: Payloads never leave this browser. We cannot see, store, or send them. We collect stats, without tracking cookies, to understand how the site is used. - Always free: No account, no paid tier, and no watermark. - Any device: Works on any phone, tablet, or computer with a browser. ## What this site is not - It does not upload payloads to a server or provide an API. - It does not convert photos. Use [Online Image Converter](https://onlineimageconverter.net/) for that. - It does not merge, split, or compress PDFs. Use [LoveThisPDF](https://lovethispdf.com/) for that. ## Categories - [Web](https://toolbuddy.dev/categories/web): Format JSON, HTML, CSS, JS, XML, SQL, Markdown, URLs, and regex. - [Convert](https://toolbuddy.dev/categories/convert): JSON, YAML, TOML, XML, CSV, SQL, timestamps, cron, colors, and cases. - [Encode](https://toolbuddy.dev/categories/encode): Base64, Base32, HTML entities, JSON strings, and ROT13. - [Crypto](https://toolbuddy.dev/categories/crypto): Hashes, HMAC, JWTs, and AES-GCM without uploading secrets. - [Generate](https://toolbuddy.dev/categories/generate): UUIDs, passwords, tokens, mock JSON, and QR codes. - [Ops](https://toolbuddy.dev/categories/ops): .env, Docker, gitignore, curl, and GitHub Actions. ## Tools - [Home](https://toolbuddy.dev/): Directory of in-browser developer tools. Format, convert, encode, hash, and generate without uploading. - [JSON Formatter](https://toolbuddy.dev/tools/json-formatter): Format JSON in your browser: beautify with 2- or 4-space indent, minify into a single line, and validate as you paste. Optional key sorting makes diffs and config reviews easier. Syntax errors report a line and column so you can jump to the bad token instead of staring at a generic 'Unexpected token' banner. - [JavaScript Formatter](https://toolbuddy.dev/tools/javascript-formatter): Beautify JavaScript with js-beautify or compact it for a rough size check. Minify here is a compact pretty-print, not a production pipeline like Terser. Keep CI minifiers for shipping bundles. Proprietary scripts stay in the tab instead of a 'JS pretty print' upload form. - [SQL Formatter](https://toolbuddy.dev/tools/sql-formatter): Beautify SQL in the browser with sql-formatter. Pick a dialect (generic SQL, PostgreSQL, MySQL, SQLite, T-SQL) and 2- or 4-space indent. Keywords are uppercased so a pasted one-liner becomes a readable query. - [HTML Formatter](https://toolbuddy.dev/tools/html-formatter): Beautify HTML with js-beautify or minify with a best-effort whitespace collapse. Imperfect markup should not crash the tab. If beautify throws, you get the original back with a note instead of a blank pane. - [CSS Formatter](https://toolbuddy.dev/tools/css-formatter): Pretty-print or minify CSS in the tab. Beautify uses js-beautify; minify strips comments and extra space. Proprietary stylesheets stay on your computer instead of a 'CSS pretty print' upload form. - [XML Formatter](https://toolbuddy.dev/tools/xml-formatter): Pretty-print or minify XML in the browser. Beautify re-indents nested elements; minify collapses comments and extra space. SOAP envelopes, RSS feeds, and Maven-ish config stay on the device instead of an XML pretty-print host. - [URL Encoder](https://toolbuddy.dev/tools/url-encoder): Percent-encode with encodeURIComponent (query values, path segments) or encodeURI (full URL mode that keeps : / ? #). Decode accepts + as space so form-encoded query strings round-trip the way browsers build them. - [URL Parser](https://toolbuddy.dev/tools/url-parser): Parse a URL into protocol, username, host, port, path, query, hash, and origin with the browser URL constructor. Query parameters are grouped as arrays so repeated keys stay visible. Missing schemes are tried as https:// so a bare host still parses. - [HTML Escape](https://toolbuddy.dev/tools/html-entities): Escape <, >, &, and quotes into HTML entities, or decode entities back to characters. Named entities such as   and numeric forms are handled on decode. Useful when you need a snippet that will not break a template. - [JSON Escape](https://toolbuddy.dev/tools/json-escape): Escape a string so it can sit inside JSON: quotes, backslashes, and control characters become \ sequences. Unescape reverses a JSON string literal (without requiring surrounding quotes). Built on JSON.stringify / JSON.parse in the tab. - [Strip HTML](https://toolbuddy.dev/tools/strip-html): Strip HTML tags to recover readable text from emails, CMS exports, and scraped fragments. Line-breaking tags such as br, p, and headings become newlines before tags are removed so paragraphs do not smash together. - [Markdown Editor](https://toolbuddy.dev/tools/markdown-editor): Write GitHub-flavored Markdown with a live HTML preview. marked renders; DOMPurify sanitizes before inject so a pasted README cannot run script. Toolbar helpers wrap bold, italic, links, code, and lists. The editor library loads on demand so other tools stay light. - [Mermaid Diagram](https://toolbuddy.dev/tools/mermaid-diagram): Render Mermaid flowcharts, sequence diagrams, and other DSL in the browser. The mermaid library is lazy-loaded with next/dynamic and ssr: false, then diagrams re-render on a short debounce as you type. A loading state appears until the library is ready. - [Text Diff](https://toolbuddy.dev/tools/text-diff): Compare two text blocks with a line-based diff (Myers via the diff library). Additions and deletions are highlighted; copy a simple unified-style patch from the tool bar. Swap panes to reverse the comparison without re-pasting. - [Regex Tester](https://toolbuddy.dev/tools/regex-tester): Test JavaScript regular expressions locally. Toggle g, i, m, s, u, and y, highlight matches in the haystack, and list capture groups. Optional replace uses the same flags and String.replace rules, including $1 backreferences. - Q: Is this PCRE or Python re? A: No. It is the JavaScript RegExp engine in this browser, including the flags you toggle. Lookbehinds and Unicode sets depend on the browser version. - [JSON ↔ YAML](https://toolbuddy.dev/tools/json-yaml): Convert JSON to YAML and YAML to JSON with js-yaml in the browser. Maps, lists, and scalars round-trip for typical config: Docker Compose-ish files, GitHub Actions fragments, and API fixtures. Anchors and custom tags are not a goal. This is dump/load, not a Kubernetes admission controller. - Q: Will my YAML comments survive? A: No. Load/dump does not round-trip comments or custom tags. Keep the original file if comments matter. - [JSON ↔ TOML](https://toolbuddy.dev/tools/json-toml): Convert a JSON object to TOML and TOML back to JSON with smol-toml in the browser. Typical use is Cargo.toml-style config, pyproject fragments, and app settings that you would rather not paste into a hosted converter. - [JSON ↔ XML](https://toolbuddy.dev/tools/json-xml): Convert JSON objects to a simple XML tree and XML documents back to JSON. Arrays become repeated child tags; primitives become text nodes. XML parsing uses the browser DOMParser. No XSLT host and no schema fetch. - [JSON ↔ CSV](https://toolbuddy.dev/tools/json-csv): Turn an array of JSON objects into CSV with a union of keys as the header, or parse CSV into an array of objects. Quoted fields and doubled quotes follow common spreadsheet rules. Nested objects are stringified into a cell rather than exploded into columns. - [JSON to SQL](https://toolbuddy.dev/tools/json-sql): Turn a JSON object or array of objects into SQL INSERT statements. Column names are the union of object keys. Strings are quoted, booleans become TRUE/FALSE, null becomes NULL, and nested objects are stored as JSON text. - Q: Can I convert SQL back to JSON? A: Not in this tool. It only builds INSERT statements from objects. Use JSON to CSV if you needed a table export instead. - [CSV ↔ TSV](https://toolbuddy.dev/tools/csv-tsv): Swap comma-separated values for tab-separated values while keeping quoted fields intact. Useful when a dump needs to paste into a console that treats commas as arguments, or the reverse for a spreadsheet. - [Timestamp Converter](https://toolbuddy.dev/tools/timestamp-converter): Convert Unix time (seconds or milliseconds) and ISO 8601 strings in both directions. Empty input follows the live clock; Now buttons stamp seconds or milliseconds. Local formatting uses Intl and your resolved IANA time zone so 'what is this epoch?' does not require a time API. - [Cron Parser](https://toolbuddy.dev/tools/cron-parser): Explain a cron expression in plain English and list the next run times in your resolved time zone. 5-field crontab lines and 6-field expressions with seconds are both accepted. Next runs use the local IANA zone from the browser. - Q: Do you support seconds? A: Yes. A 6-field expression is treated as seconds minutes hours day-of-month month day-of-week. Standard 5-field crontab lines work too. - [Case Converter](https://toolbuddy.dev/tools/case-converter): Convert identifiers between camelCase, PascalCase, snake_case, kebab-case, CONSTANT_CASE, and URL slugs. Each line is converted on its own so you can paste a list of names from a schema or a route table. - [Color Converter](https://toolbuddy.dev/tools/color-converter): Convert HEX, RGB, HSL, and CMYK with a live swatch and a native color picker. Copy each CSS form independently or copy HEX from the sticky bar. Values clamp to valid ranges so a typo cannot produce NaN tokens in a stylesheet. - [Number Base Converter](https://toolbuddy.dev/tools/number-base): Convert integers between binary, octal, decimal, and hexadecimal using BigInt, so values larger than 32-bit still round-trip. Hex input may include a 0x prefix; underscores and spaces are ignored. - [Hex Converter](https://toolbuddy.dev/tools/hex-text): Encode UTF-8 text as space-separated hex bytes, or decode hex (spaces and 0-9a-f) back to text. Odd-length hex fails fast so you do not get a truncated character. - [Binary Converter](https://toolbuddy.dev/tools/binary-text): Convert UTF-8 text to 8-bit groups and binary back to text. Spaces are ignored on decode; length must be a multiple of 8 and only 0/1 are allowed. - Q: Why did decode fail? A: Input must be only 0 and 1, and the bit length must be a multiple of 8. Spaces are ignored; other characters are not. - [IPv4 Converter](https://toolbuddy.dev/tools/ip-converter): Convert IPv4 between dotted decimal, unsigned 32-bit integer, hex, and dotted binary. Databases that store INET as numbers, and packet notes that print hex IPs, round-trip here. IPv6 is out of scope. - Q: Do you detect my public IP? A: No. That would require a server or a third-party echo API. This tool only converts an address you paste. - [Data Size Converter](https://toolbuddy.dev/tools/data-size-converter): Convert a byte count between decimal units (KB, MB, GB, TB, PB, powers of 1000) and binary units (KiB, MiB, GiB, TiB, PiB, powers of 1024). Disk makers use the first, and many operating systems and tools report the second. - [CSS Unit Converter](https://toolbuddy.dev/tools/css-unit-converter): Convert CSS lengths between px, rem, em, pt, pc, in, cm, and mm. Absolute units use the CSS reference of 96px per inch. rem and em follow the base font size you set, 16px by default. - [Duration Converter](https://toolbuddy.dev/tools/duration-converter): Convert a duration between milliseconds, seconds, minutes, hours, days, ISO 8601, and a short readable form such as 1h 30m. Useful for timeouts, cache TTLs, and cron gaps written in whichever unit the config file prefers. - [Base64 Encoder](https://toolbuddy.dev/tools/base64-encoder): Encode and decode Base64 with UTF-8 text, including the URL-safe alphabet (- and _). Decoding accepts standard or URL-safe input and restores padding when needed, so a truncated Data URI payload still has a chance to round-trip. - [Base32 Encoder](https://toolbuddy.dev/tools/base32-encoder): Encode and decode RFC 4648 Base32 (A–Z and 2–7, with = padding). Decode is case-insensitive and ignores whitespace. Invalid alphabets fail instead of silently skipping characters. - [ROT13](https://toolbuddy.dev/tools/rot13): ROT13 rotates Latin letters by 13 places; digits and punctuation pass through. Applying it twice restores the original, so both direction pills run the same transform. - [Hash Generator](https://toolbuddy.dev/tools/hash-generator): Hash text or a local file with MD5 (SparkMD5), SHA-1, SHA-256, or SHA-512. SHA family uses Web Crypto; output is hex and Base64. File hashing reads an ArrayBuffer in the tab. The file is not uploaded to a checksum SaaS. - [HMAC Generator](https://toolbuddy.dev/tools/hmac-generator): Compute HMAC with Web Crypto: SHA-1, SHA-256, SHA-384, or SHA-512. Paste a message and a secret, then copy hex or Base64. Typical use is checking a webhook signature or minting a test header without sending the key to a hosted HMAC site. - [JWT Decoder](https://toolbuddy.dev/tools/jwt-decoder): Decode a JSON Web Token into header, payload, and signature without sending the token to an identity provider. Claims such as exp, iat, and nbf are shown as ISO and local times. By default the banner reads 'Signature not verified' so a decoded token is never mistaken for an authenticated session. - [AES Encrypt](https://toolbuddy.dev/tools/aes-encrypt): Encrypt and decrypt UTF-8 text with AES-256-GCM in Web Crypto. A password is stretched with PBKDF2 (SHA-256, 100k iterations, random 16-byte salt). Output is Base64 of salt + 12-byte IV + ciphertext so a single string is enough to decrypt later. - Q: Can I decrypt this elsewhere? A: Yes, if the other side uses AES-256-GCM, the same PBKDF2 parameters (SHA-256, 100k iterations), and the packed layout salt(16) + IV(12) + ciphertext. Many generic 'AES' websites use different packing, so they will not decode this blob. - Q: Is this end-to-end encryption for production? A: No. It is a local experiment tool. Use a real protocol (TLS, age, Signal, a KMS) for production secrets. - [UUID Generator](https://toolbuddy.dev/tools/uuid-generator): Generate UUID v4 with crypto.randomUUID and UUID v7 (Unix-ms time-ordered) in bulk from 1 to 100, or switch to Validate to check and reformat pasted IDs. Both generated versions set the IETF variant bits so libraries accept them as RFC 4122-style IDs. - [Password Generator](https://toolbuddy.dev/tools/password-generator): Build passwords from uppercase, lowercase, digits, and symbols, with an option to drop ambiguous 0/O/I/l/1. Generate a single secret or a bulk list. A simple entropy meter estimates bits as length × log2(charset size) so you can see when a short charset is too weak. - [Random String Generator](https://toolbuddy.dev/tools/random-string): Build a random string from letters, digits, dash/underscore, and extra characters you type. Length is capped; values come from crypto.getRandomValues, not Math.random. Hit Generate when you want a new token without changing length. If every charset toggle is off and the extra box is empty, output is empty rather than a fake default. - Q: Is this a password generator? A: It can make random tokens, but the dedicated password tool adds charset guidance and an entropy hint. Use that for secrets you will type often. - [Random JSON Generator](https://toolbuddy.dev/tools/random-json): Generate nested JSON objects and arrays for mocks: ids, names, flags, counts, and small maps. Depth and root item count are capped so a typo cannot freeze the tab. Values use crypto.getRandomValues and crypto.randomUUID. - [Random Number Generator](https://toolbuddy.dev/tools/random-number): Draw random integers or decimals between a minimum and a maximum, one value or a list. Sampling uses crypto.getRandomValues scaled into the range. Decimal places from 0 to 8 cover money-like fixtures and scientific dummy data. If min is greater than max they swap internally so the range is always valid. - [QR Code Generator](https://toolbuddy.dev/tools/qr-generator): Encode a URL or any text as a QR code in the browser. Error correction L through H, pixel size, quiet zone, and dark/light colors are local options. Download PNG or SVG, or copy SVG from the sticky bar. - [Line Tools](https://toolbuddy.dev/tools/line-tools): Sort, dedupe, reverse, shuffle, or trim lines in the browser. Shuffle uses crypto.getRandomValues. Useful for log lists and config dumps you would rather not paste into an online sorter. - [JSON Repair](https://toolbuddy.dev/tools/json-repair): Repair messy JSON: trailing commas, comments, and unquoted keys, then pretty-print. Built on jsonrepair in the tab so broken fixtures stay on the device. - [JSON to JSON Schema](https://toolbuddy.dev/tools/json-schema): Infer a JSON Schema from a sample. Object keys become properties; the first array item sets items. Required lists every key present in the sample. - [JSON Diff](https://toolbuddy.dev/tools/json-diff): Diff two JSON documents by path instead of by line. Added, removed, and changed values are listed with JSON-style pointers. - [JSONPath Tester](https://toolbuddy.dev/tools/jsonpath-tester): Query JSON with JSONPath. Paths such as $.users[*].name run in the browser via jsonpath-plus. - [JSON-LD Inspector](https://toolbuddy.dev/tools/jsonld-inspector): Inspect JSON-LD from a raw document or a script type=application/ld+json tag. @type, @context, and keys are summarized. - [JSON to Code](https://toolbuddy.dev/tools/php-array): Convert JSON into JS, Python, or PHP literals. JS uses const data, Python uses True/False/None, PHP uses short arrays and => pairs. Strings in PHP are single-quoted. - [CSV to SQL](https://toolbuddy.dev/tools/csv-sql): Turn CSV into INSERT statements. The header row is the column list. Values are quoted like the JSON to SQL tool. - [CSV Query](https://toolbuddy.dev/tools/csv-query): Run a small SQL subset on CSV in memory: SELECT, WHERE col = value, ORDER BY, LIMIT. Results render as a text table. - [Color Contrast](https://toolbuddy.dev/tools/color-contrast): Compute WCAG 2 contrast between two colors. AA normal text needs 4.5:1; large text 3:1; AAA 7:1 / 4.5:1. - [String Length](https://toolbuddy.dev/tools/string-length): Count characters, non-space characters, words, lines, and UTF-8 bytes. Byte size uses TextEncoder. - [Big Number](https://toolbuddy.dev/tools/big-number): Integer math with BigInt: add, subtract, multiply, divide, modulo, and power. Division truncates toward zero. - [Gitignore Generator](https://toolbuddy.dev/tools/gitignore-generator): Stack .gitignore snippets for Node, Python, Go, Rust, Java, Next.js, macOS, and Windows. - [.env Toolkit](https://toolbuddy.dev/tools/env-toolkit): Parse dotenv files, list keys, flag duplicates and empty values, and diff two env blobs. - [Docker Generator](https://toolbuddy.dev/tools/docker-generator): Generate a Dockerfile or Compose service from image, workdir, ports, and command. - [GitHub Actions Explainer](https://toolbuddy.dev/tools/github-actions-explainer): Summarize a GitHub Actions workflow: name, on triggers, jobs, runs-on, and step names or uses. - [cURL Generator](https://toolbuddy.dev/tools/curl-generator): Assemble a curl command from method, URL, headers, and body. Quotes are added when the token needs them. - [Tar Command Generator](https://toolbuddy.dev/tools/tar-generator): Build tar create or extract commands with optional gz, bz2, or xz. Archive name and paths are fields. - [MySQL Command Generator](https://toolbuddy.dev/tools/mysql-generator): Build mysql or mysqldump command lines. Host, user, and database are fields. The password flag is -p so you are prompted locally. - [cURL to Code](https://toolbuddy.dev/tools/curl-to-code): Parse curl -X, -H, and --data into JS fetch, Node http/https, Python requests, PHP curl, or axios. Quoted tokens are supported. - [Secret Redactor](https://toolbuddy.dev/tools/secret-redactor): Replace JWTs, AWS access keys, GitHub tokens, Slack tokens, PEM private keys, bearer tokens, emails, and UUIDs with labeled placeholders. - [Security Headers](https://toolbuddy.dev/tools/security-headers): Audit pasted response headers for CSP, HSTS, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy, and related COOP/CORP headers. - [XML Validator](https://toolbuddy.dev/tools/xml-validator): Check well-formed XML with DOMParser. parsererror text is shown when the document is not well-formed. - [XPath Tester](https://toolbuddy.dev/tools/xpath-tester): Evaluate XPath against pasted XML using document.evaluate. Node text is listed, one match per line. - [Template String](https://toolbuddy.dev/tools/template-string): Replace ${dotted.path} and {{ dotted.path }} from a JSON object. Missing paths become empty strings. - [Stack Trace Formatter](https://toolbuddy.dev/tools/stack-trace): Pretty-print JavaScript at frames, Java at Class.method(File:line), and Go panic stacks. - [HTTP Status Codes](https://toolbuddy.dev/tools/http-status): Filter common HTTP status codes by number or phrase. 2xx, 3xx, 4xx, and 5xx staples are included. - [Timezone Compare](https://toolbuddy.dev/tools/timezone-compare): Format an instant in several IANA zones with Intl. Empty input uses now. Invalid zones are skipped. ## Related - [Online Image Converter](https://onlineimageconverter.net/): Convert, resize, and compress photos in the browser. - [LoveThisPDF](https://lovethispdf.com/): Merge, split, and compress PDFs in the browser. ## Optional - [Privacy](https://toolbuddy.dev/privacy): Payloads stay on the device. Stats without tracking cookies. - [llms.txt](https://toolbuddy.dev/llms.txt): Short machine-readable summary of this site. - [llms-full.txt](https://toolbuddy.dev/llms-full.txt): Longer summary for language models. - [Sitemap](https://toolbuddy.dev/sitemap.xml): Machine-readable list of public URLs.