# ToolBuddy > Free browser tools. Private by design. ToolBuddy is a static website at https://toolbuddy.dev. Developer tools run in the visitor's browser on any phone, tablet, or computer. Format JSON, decode JWTs, convert YAML, generate hashes, and more entirely on your device. There is no upload API, no account, and no paid tier. Payloads are not sent to or stored by the site. Crawling, indexing, training, and quoting this site is welcome. ## Categories - [Web](https://toolbuddy.dev/categories/web): Format JSON, HTML, CSS, JS, XML, SQL, Markdown, URLs, and regex. - [Convert](https://toolbuddy.dev/categories/convert): JSON, YAML, TOML, XML, CSV, SQL, timestamps, cron, colors, and cases. - [Encode](https://toolbuddy.dev/categories/encode): Base64, Base32, HTML entities, JSON strings, and ROT13. - [Crypto](https://toolbuddy.dev/categories/crypto): Hashes, HMAC, JWTs, and AES-GCM without uploading secrets. - [Generate](https://toolbuddy.dev/categories/generate): UUIDs, passwords, tokens, mock JSON, and QR codes. - [Ops](https://toolbuddy.dev/categories/ops): .env, Docker, gitignore, curl, and GitHub Actions. ## Tools - [Home](https://toolbuddy.dev/): Directory of in-browser developer tools. Format, convert, encode, hash, and generate without uploading. - [JSON Formatter](https://toolbuddy.dev/tools/json-formatter): Pretty-print, minify, and validate JSON in your browser. Paste a payload, fix indentation, and spot syntax errors without sending data to a server. Works for APIs, config files, and nested objects. Output stays on your device. - [JavaScript Formatter](https://toolbuddy.dev/tools/javascript-formatter): Beautify or compact JavaScript in the browser. Re-indent minified snippets from DevTools, or collapse whitespace for a rough size check. Formatting stays on-device so proprietary scripts are never posted to a beautifier. - [SQL Formatter](https://toolbuddy.dev/tools/sql-formatter): Beautify SQL in the browser with dialect-aware formatting for PostgreSQL, MySQL, SQLite, and T-SQL. Paste a query, pick indent, and copy readable SQL without sending statements to a formatter service. - [HTML Formatter](https://toolbuddy.dev/tools/html-formatter): Beautify or minify HTML markup locally. Re-indent nested tags, collapse whitespace for production snippets, and copy formatted markup without posting templates to a formatter service. Handy for emails, partials, and messy copy-paste from DevTools. - [CSS Formatter](https://toolbuddy.dev/tools/css-formatter): Format and minify CSS in the browser. Expand rules for readability or compress stylesheets for a quick size check. Paste a snippet, tidy selectors and declarations, and copy the result. Proprietary styles are not uploaded. - [XML Formatter](https://toolbuddy.dev/tools/xml-formatter): Pretty-print or minify XML documents in your browser. Indent nested elements from SOAP, RSS, and config files, or collapse whitespace for a compact blob. Parsing and formatting never leave the tab. - [URL Encoder](https://toolbuddy.dev/tools/url-encoder): Percent-encode and decode URLs and query parameters with encodeURIComponent-style rules. Fix broken links, escape reserved characters, and inspect encoded query strings locally. A small, private alternative to sending URLs through an online encoder. - [URL Parser](https://toolbuddy.dev/tools/url-parser): Split a URL into protocol, host, port, path, query, and hash using the browser URL API. Inspect search params as JSON without a remote parser. Useful when a log line is one long encoded address. - [HTML Escape](https://toolbuddy.dev/tools/html-entities): Escape and unescape HTML entities in the browser. Turn <, >, &, and quotes into entities for safe snippets, or decode & back to characters. Nothing is uploaded. Useful for templates and email HTML. - [JSON Escape](https://toolbuddy.dev/tools/json-escape): Escape a string for use inside JSON (quotes, backslashes, and control characters) or unescape a JSON string literal. Runs with JSON.stringify / JSON.parse in your tab so fixture text never hits a hosted escaper. - [Strip HTML](https://toolbuddy.dev/tools/strip-html): Convert HTML snippets to plain text by stripping tags and optionally decoding entities. Extract readable copy from emails, CMS exports, and scraped fragments without sending markup to a sanitizer API. - [Markdown Editor](https://toolbuddy.dev/tools/markdown-editor): Write Markdown with a live preview in your browser. Draft README sections, docs, and comments, then copy Markdown or rendered HTML. Preview stays on-device so unpublished docs and internal notes are not sent to a cloud editor. - [Mermaid Diagram](https://toolbuddy.dev/tools/mermaid-diagram): Render Mermaid diagrams from text: flowcharts, sequence diagrams, ER charts, and more. Paste DSL, preview the graph, and copy the source for docs. Rendering is client-side so architecture sketches do not leave your machine. - [Text Diff](https://toolbuddy.dev/tools/text-diff): Compare two blocks of text and highlight additions, deletions, and unchanged lines. Useful for config reviews, copy edits, and log snippets when you do not want to paste sensitive diffs into an online checker. All comparison happens locally. - [Regex Tester](https://toolbuddy.dev/tools/regex-tester): Test JavaScript regular expressions in the browser. Paste a pattern and a string, toggle flags, see highlighted matches and capture groups, then copy matches or a replace result. Patterns never leave the tab. - [JSON ↔ YAML](https://toolbuddy.dev/tools/json-yaml): Convert JSON to YAML and YAML back to JSON in the browser. Paste a config, Kubernetes snippet, or API fixture and copy the other format. Parsing uses js-yaml locally. Documents are never posted to a converter. - [JSON ↔ TOML](https://toolbuddy.dev/tools/json-toml): Convert JSON objects to TOML and TOML documents back to JSON in the browser. Handy for Cargo.toml, pyproject, and app config fragments. Parsing stays on-device. - [JSON ↔ XML](https://toolbuddy.dev/tools/json-xml): Convert JSON objects to XML and XML documents back to JSON. Useful for SOAP leftovers, RSS, and mixed API stacks. XML is parsed with the browser DOMParser so payloads stay on the device. - [JSON ↔ CSV](https://toolbuddy.dev/tools/json-csv): Turn an array of JSON objects into CSV, or parse CSV headers into JSON objects. Quote-aware parsing runs in the tab so spreadsheets of IDs and emails are not uploaded to a conversion service. - [JSON to SQL](https://toolbuddy.dev/tools/json-sql): Turn a JSON object or array of objects into SQL INSERT statements. Set a table name, copy the query, and keep rows on the device instead of pasting fixtures into a hosted converter. - [CSV ↔ TSV](https://toolbuddy.dev/tools/csv-tsv): Convert comma-separated values to tab-separated values and back, preserving quoted fields. A small delimiter swap for dumps you would rather not paste into a spreadsheet SaaS. - [Timestamp Converter](https://toolbuddy.dev/tools/timestamp-converter): Convert Unix timestamps, milliseconds, and ISO 8601 dates in both directions. See UTC and local time side by side, generate a 'now' epoch, and copy values for logs, databases, and APIs without a round trip to a conversion API. - [Cron Parser](https://toolbuddy.dev/tools/cron-parser): Explain a cron expression in plain English, list the next run times in your local time zone, and edit fields or presets. Paste a 5- or 6-field crontab line. Parsing is local, so job schedules never hit a cron API. - [Case Converter](https://toolbuddy.dev/tools/case-converter): Convert identifiers between camelCase, PascalCase, snake_case, kebab-case, CONSTANT_CASE, and URL slugs. Paste one name or a list, one per line. Conversion is a local string transform. - [Color Converter](https://toolbuddy.dev/tools/color-converter): Convert colors between HEX, RGB, HSL, CMYK, and related CSS notations. Preview swatches, copy values for design tokens, and translate picker output into code. Runs entirely in the tab so brand palettes never hit a third-party converter. - [Number Base Converter](https://toolbuddy.dev/tools/number-base): Convert integers between binary, octal, decimal, and hexadecimal. Uses BigInt so large IDs and bit masks still round-trip. All math is local. There is no integer-conversion API. - [Hex Converter](https://toolbuddy.dev/tools/hex-text): Encode UTF-8 text as hexadecimal bytes and decode hex back to text. Inspect packet dumps, color-ish strings, and binary-safe debug output without a remote hex encoder. - [Binary Converter](https://toolbuddy.dev/tools/binary-text): Convert text to binary and binary back to text. Inspect UTF-8 bit patterns, homework encodings, and simple wire dumps. Conversion stays on-device with copyable 0s and 1s. - [IPv4 Converter](https://toolbuddy.dev/tools/ip-converter): Convert IPv4 addresses between dotted decimal, unsigned integer, hex, and dotted binary. Useful when a database stores IPs as numbers. Parsing is local IPv4 math. No geo lookup and no 'what is my IP' lookup. - [Data Size Converter](https://toolbuddy.dev/tools/data-size-converter): Convert bytes between decimal units (KB, MB, GB, TB) and binary units (KiB, MiB, GiB, TiB). See why a 500 GB disk shows up as 465 GiB. The math runs in the tab. - [CSS Unit Converter](https://toolbuddy.dev/tools/css-unit-converter): Convert CSS lengths between px, rem, em, pt, pc, in, cm, and mm. Set the base font size to match your root, then copy the value you need. Conversion is local. - [Duration Converter](https://toolbuddy.dev/tools/duration-converter): Convert durations between milliseconds, seconds, minutes, hours, days, and ISO 8601 (PT1H30M). Paste 1h 30m, 5400s, or a timeout from a config file. Parsing stays on-device. - [Base64 Encoder](https://toolbuddy.dev/tools/base64-encoder): Encode and decode Base64 (and UTF-8 text) instantly in the browser. Convert strings for Data URIs, HTTP headers, and binary-safe transport. Nothing is uploaded, so you can encode without pasting secrets into a public encoder. - [Base32 Encoder](https://toolbuddy.dev/tools/base32-encoder): Encode and decode RFC 4648 Base32 in the browser. Handy for OTP secrets, human-typed tokens, and case-insensitive transport. Codec runs locally with no upload. - [ROT13](https://toolbuddy.dev/tools/rot13): Apply ROT13 to text in either direction (the cipher is its own inverse). A classic Caesar shift for puzzles and lightly obfuscated spoilers, not encryption. Runs entirely in the tab. - [Hash Generator](https://toolbuddy.dev/tools/hash-generator): Generate cryptographic hashes (SHA-256, SHA-1, MD5, and more) from text using Web Crypto in your browser. Create checksums for files-as-text, compare digests, and copy hex output. Hashing never leaves the tab, so test strings and secrets stay private. - [HMAC Generator](https://toolbuddy.dev/tools/hmac-generator): Compute HMAC-SHA signatures in the browser for webhook secrets and API signing. Paste a message and a key, pick SHA-1 through SHA-512, and copy hex or Base64. Keys stay in the tab. - [JWT Decoder](https://toolbuddy.dev/tools/jwt-decoder): Decode JSON Web Tokens locally to inspect the header, payload, and expiry claims. Paste a JWT and read Base64URL-encoded fields without verifying signatures on a remote service. Ideal for debugging auth flows while keeping tokens off the network. - [AES Encrypt](https://toolbuddy.dev/tools/aes-encrypt): Encrypt and decrypt text with AES-256-GCM in the browser. A password is stretched with PBKDF2; output is Base64(salt + IV + ciphertext). Useful for sharing a short secret over a side channel you control. Keys never leave the tab. - [UUID Generator](https://toolbuddy.dev/tools/uuid-generator): Generate RFC 4122 UUIDs (v4 and v7) in bulk, or validate and reformat pasted IDs. Copy a list for database seeds, test fixtures, and idempotency keys. Uses the Web Crypto RNG so IDs are created on-device with no telemetry. - [Password Generator](https://toolbuddy.dev/tools/password-generator): Create strong random passwords and passphrases in your browser. Tune length, symbols, and ambiguity, then copy once. Generation uses local randomness and never phones home. A private generator for accounts, test users, and sharing secrets over a side channel you control. - [Random String Generator](https://toolbuddy.dev/tools/random-string): Generate random alphanumeric strings with a charset and length you choose. Handy for tokens, test IDs, and dummy keys. Uses local randomness so generated values are not logged by a hosted generator. - [Random JSON Generator](https://toolbuddy.dev/tools/random-json): Generate nested JSON fixtures for mocks and tests. Tune depth and item count, then copy a valid object or array. Built with the Web Crypto RNG so dummy payloads are created on-device. - [Random Number Generator](https://toolbuddy.dev/tools/random-number): Pick random integers or decimals in a min–max range, one at a time or in a list. Simple test data and dice-style rolls without a remote RNG. Generated on your device. - [QR Code Generator](https://toolbuddy.dev/tools/qr-generator): Encode a URL or any text as a QR code in the browser. Tune error correction, size, and colors, then download PNG or SVG. Encoding stays on the device. There is no QR API. - [Line Tools](https://toolbuddy.dev/tools/line-tools): Sort, dedupe, reverse, shuffle, or trim lines in the browser. Paste a list from a log or a config file and copy the result. Processing stays on the device. - [JSON Repair](https://toolbuddy.dev/tools/json-repair): Repair common JSON mistakes such as trailing commas, comments, and unquoted keys, then pretty-print the result. Runs locally so broken fixtures are not posted to a fixer. - [JSON to JSON Schema](https://toolbuddy.dev/tools/json-schema): Infer a JSON Schema from a sample object or array. Types, properties, and required keys are derived in the tab. A starting point for API contracts, not a full draft-2020 generator. - [JSON Diff](https://toolbuddy.dev/tools/json-diff): Compare two JSON documents by path. See added, removed, and changed values without a line-based text diff. Comparison is local. - [JSONPath Tester](https://toolbuddy.dev/tools/jsonpath-tester): Query JSON with JSONPath in the browser. Paste a document, enter a path such as $.users[*].id, and copy matching values. No remote query engine. - [JSON-LD Inspector](https://toolbuddy.dev/tools/jsonld-inspector): Inspect pasted JSON-LD or a script type=application/ld+json block. See @type, @context, and keys without fetching a page. Parsing stays on-device. - [JSON to Code](https://toolbuddy.dev/tools/php-array): Convert JSON into JS, Python, or PHP literals. Objects become dicts or arrays with key => value pairs. Conversion is a local string transform. - [CSV to SQL](https://toolbuddy.dev/tools/csv-sql): Turn CSV into SQL INSERT statements. The header row becomes columns. Rows stay in the tab. - [CSV Query](https://toolbuddy.dev/tools/csv-query): Preview CSV as a table and run a small SQL subset: SELECT, WHERE, ORDER BY, LIMIT. Querying is in-memory in this tab. - [Color Contrast](https://toolbuddy.dev/tools/color-contrast): Check WCAG contrast between two colors. Paste HEX, RGB, or HSL for foreground and background. Ratio math is local. - [String Length](https://toolbuddy.dev/tools/string-length): Count characters, words, lines, and UTF-8 bytes for a pasted string. Useful for payload size checks. Counting is local. - [Big Number](https://toolbuddy.dev/tools/big-number): Add, subtract, multiply, divide, and raise integers larger than Number.MAX_SAFE_INTEGER using BigInt. Math stays in the tab. - [Gitignore Generator](https://toolbuddy.dev/tools/gitignore-generator): Build a .gitignore from stacked templates for Node, Python, Go, Rust, Java, Next.js, macOS, and Windows. Output is composed locally. - [.env Toolkit](https://toolbuddy.dev/tools/env-toolkit): Parse KEY=value env files, flag duplicates, and diff two .env blobs. Secrets in env files never leave the browser. - [Docker Generator](https://toolbuddy.dev/tools/docker-generator): Generate a Dockerfile or a Compose service snippet from image, ports, and command fields. Snippets are built in the tab. - [GitHub Actions Explainer](https://toolbuddy.dev/tools/github-actions-explainer): Explain a GitHub Actions workflow YAML: name, triggers, jobs, and steps. Parsing uses js-yaml in the browser. - [cURL Generator](https://toolbuddy.dev/tools/curl-generator): Build a curl command from method, URL, headers, and body. The command is assembled locally so tokens in headers stay in the tab. - [Tar Command Generator](https://toolbuddy.dev/tools/tar-generator): Build a tar create or extract command with gz, bz2, or xz flags. A small command helper, not an archiver. - [MySQL Command Generator](https://toolbuddy.dev/tools/mysql-generator): Build mysql or mysqldump command lines from user, host, and database. The command is text only; it does not connect to a server. - [cURL to Code](https://toolbuddy.dev/tools/curl-to-code): Convert a curl command into JS fetch, Node http, Python requests, PHP curl, or axios. Parsing is local and covers -X, -H, and --data. - [Secret Redactor](https://toolbuddy.dev/tools/secret-redactor): Redact JWTs, AWS keys, GitHub tokens, private keys, bearer tokens, and emails in pasted logs. Replacement happens in the tab. - [Security Headers](https://toolbuddy.dev/tools/security-headers): Audit pasted HTTP response headers for CSP, HSTS, X-Frame-Options, and related controls. No URL is fetched. - [XML Validator](https://toolbuddy.dev/tools/xml-validator): Check that XML is well-formed using the browser DOMParser. This is not XSD or DTD validation and does not fetch schemas. - [XPath Tester](https://toolbuddy.dev/tools/xpath-tester): Evaluate an XPath expression against pasted XML in the browser. Matching node text is listed. No remote XML processor. - [Template String](https://toolbuddy.dev/tools/template-string): Fill ${path} or {{ path }} placeholders from a JSON object. Rendering is a local string replace. - [Stack Trace Formatter](https://toolbuddy.dev/tools/stack-trace): Pretty-print JavaScript, Java, and Go stack traces. Frames are indented for reading. Formatting is local. - [HTTP Status Codes](https://toolbuddy.dev/tools/http-status): Look up common HTTP status codes and filter by number or name. A local reference, not a live request inspector. - [Timezone Compare](https://toolbuddy.dev/tools/timezone-compare): Show an instant in several IANA time zones using Intl. Paste ISO 8601 or leave empty for now. Conversion is local. ## Related - [Online Image Converter](https://onlineimageconverter.net/): Convert, resize, and compress photos in the browser. - [LoveThisPDF](https://lovethispdf.com/): Merge, split, and compress PDFs in the browser. ## Optional - [Privacy](https://toolbuddy.dev/privacy): Payloads stay on the device. Stats without tracking cookies. - [llms.txt](https://toolbuddy.dev/llms.txt): Short machine-readable summary of this site. - [llms-full.txt](https://toolbuddy.dev/llms-full.txt): Longer summary for language models. - [Sitemap](https://toolbuddy.dev/sitemap.xml): Machine-readable list of public URLs.