Neatbo.

Encoding and verification guide: Base64, hashes, JWT and SAML

Distinguish encoding, hashes and signature verification. Use Base64, SHA256SUMS, SSH fingerprints, JWT verification and SAML inspection with clear trust boundaries.

Choose an operation for your task

Distinguish encoding, hashes and signature verification. Use Base64, SHA256SUMS, SSH fingerprints, JWT verification and SAML inspection with clear trust boundaries.

Which operation fits?
Your taskWhere to start
Change text representationChoose the receiver’s Base64 or other encoding rules
Check whether files changedCompute a hash or compare a SHA256SUMS manifest from a trusted source
Inspect token trustDecode for inspection; verify supported JWT signatures with a trusted key

Work in order and retain the original

Agree on the exact input bytes and expected algorithm. For JWT verification, use a trusted public RSA JWK or the intended HMAC secret and pin the algorithm. Check issuer, audience and time separately from the signature. For a file batch, save SHA256SUMS separately and report missing or unexpected files, not only hash mismatches.

Representative workflow and expected result
SHA-256 of an empty file starts e3b0c442; a filename change does not change its bytes, but a manifest lookup still requires the exact name.

Separate processing success from acceptance

Compare full digests and preserve expected values through an independent channel. Never treat Base64 or quoted-printable as encryption; sensitive inputs remain local but still appear on your screen.

Before you finish

Expand a tool below for its steps, options and limits. Choose the tools needed for your task; you do not need to use every one.

  • Compare full digests and preserve expected values through an independent channel. Never treat Base64 or quoted-printable as encryption; sensitive inputs remain local but still appear on your screen.
  • Reopen the download and compare it with the example and the meaning of the input.
  • When an input exceeds the stated boundaries, retain it and split the task or use a suitable processor; renaming an extension does not make it compatible.

References

Tools in this category

Expand a tool to see its steps, options and supported formats, then open its workspace.

Base64 encode / decodeEncode or decode a snippet in a click.

Encode UTF-8 text or exact local file bytes as Base64. Strict decoding checks padding and canonical bits; choose a binary download when decoded bytes are not UTF-8. Base64 is an encoding, not encryption.

Steps

  1. Paste UTF-8 text or choose one local file of raw bytes.
  2. Choose Encode or Decode. For decoding, select UTF-8 text or a binary file and choose whether to ignore whitespace.
  3. Check the output, then copy the text or download the result.

Available options

Operation
Encode · Decode
Decoded output
UTF-8 text · Binary file
Ignore whitespace in Base64
Off by default

Capabilities and limits

  • Pasted text is limited to 1 MiB; review the result before using it.
  • One local file up to 10 MiB can be processed in this workspace.
  • When a file is selected, its bytes take priority over any pasted text.
  • The screen previews the first 4,000 characters; copy and download keep the complete result.
Open Base64 encode / decode →
URL encode / decodeMake those encoded characters readable again.

Encode or decode a URL component or a whole URL once. Whole URL mode preserves URL delimiters, and decoding + as a space is optional. Malformed percent escapes are rejected; no URL is visited.

Steps

  1. Paste the URL component or whole URL you need to convert.
  2. Choose Encode or Decode and the scope. For form-style decoding, enable + as a space.
  3. Check that separators are preserved in whole URL mode, then copy or download the result.

Available options

Operation
Encode · Decode
Encoding scope
URL component · Whole URL
Decode + as a space
Off by default

Capabilities and limits

  • Pasted text is limited to 1 MiB; review the result before using it.
  • Encoding an already percent-encoded value will encode its % signs again; inspect the input before converting.
Open URL encode / decode →
HTML entitiesConvert between HTML entities and readable characters.

Encode special HTML characters or decode semicolon-terminated HTML named entities and decimal or hexadecimal numeric references once. Output remains plain text, so decoded tags and scripts are never executed.

Steps

  1. Paste text to encode or semicolon-terminated HTML entities to decode.
  2. Choose Encode or Decode. The non-ASCII option applies only when encoding.
  3. Check the plain-text result, then copy or download it; unknown entity names remain unchanged.

Available options

Operation
Encode · Decode
Encode non-ASCII characters too
Off by default

Capabilities and limits

  • Pasted text is limited to 1 MiB; review the result before using it.
  • Unknown entity names remain unchanged; invalid numeric scalar values report an error.
  • Legacy C1 numeric references follow HTML mapping (for example, € becomes €).
Open HTML entities →
Unicode escapeConvert Unicode escapes into readable text and back.

Convert text to JavaScript-style Unicode escapes and back. Surrogate pairs are handled explicitly, while malformed escapes and unpaired surrogates are rejected.

Steps

  1. Paste text or JavaScript-style Unicode escapes, including surrogate pairs.
  2. Choose Encode or Decode; the printable-ASCII option applies only when encoding.
  3. Check the characters or escapes, then copy or download the result.

Available options

Operation
Encode · Decode
Keep printable ASCII except backslash
On by default

Capabilities and limits

  • Pasted text is limited to 1 MiB; review the result before using it.
Open Unicode escape →
SHA-256 checksumCalculate a SHA-256 checksum for text or a file.

Calculate SHA-256 over exact local file bytes, including an empty file, or the UTF-8 bytes of entered text using Web Crypto. Compare the copied digest with a trusted expected value; a digest alone does not prove file origin.

Steps

  1. Paste text or choose one local file, including an empty file.
  2. Calculate the SHA-256 digest of UTF-8 text or the file’s exact bytes.
  3. Copy or download the digest and compare it with a trusted expected value.

Capabilities and limits

  • Pasted text is limited to 1 MiB; review the result before using it.
  • One local file up to 10 MiB can be processed in this workspace.
  • When a file is selected, its bytes take priority over any pasted text.
Open SHA-256 checksum →
Inspect and verify JWTInspect complete JWT header and claims, or verify HS256 / RS256 with a separately supplied trusted key.

Choose inspection or verification. Inspection needs no key and shows unverified previews and offers complete header and claims in downloads without verifying signatures or claims; it establishes no authentication. Verification uses a separately supplied trusted secret or RSA public JWK to check HS256 / RS256 signatures, times, issuer and audience separately.

Steps

  1. Paste a JWT or choose a local JWT text file, then choose inspection or verification.
  2. Inspection needs no key. Read the unverified previews, then copy or download the complete decoded header and claims JSON.
  3. For verification, separately supply a trusted key, choose HS256 / RS256 from trusted configuration and enter expected issuer/audience when needed. Review passed, failed and skipped checks; a signature match alone is not an authorization decision.

Available options

Operation
Inspect only (unverified) · Verify signature

Inspection needs no key and verifies neither identity nor claims. Verification checks the separately supplied key and selected claims.

Expected algorithm
HS256 · RS256

Choose the algorithm from trusted service documentation, not only from the unverified token’s alg field.

Expected issuer (optional)
Enter as needed

Enter the exact expected issuer when known. Leaving it blank skips this matching check.

Expected audience (optional)
Enter as needed

Enter the audience expected by the receiver. Leaving it blank skips this matching check.

Capabilities and limits

  • Inspection accepts three Base64URL segments, including an empty signature in an alg=none example; it does not decrypt five-part JWE. Header and claims must be JSON objects; duplicate keys are rejected. Number tokens stay exact, including large integers. Each decoded JSON document is limited to nesting depth 128 and 200,000 value nodes. JSON error positions refer to the decoded document.
  • Header and claims previews each show the first 4,000 UTF-16 code units. Copy and JSON download retain the complete result; inspection reports are limited to 20 MiB.
  • RS256 accepts a public RSA JWK; HS256 accepts a shared secret. Only the supplied key is checked. The tool does not fetch JWKS, select keys by kid, or establish key origin; passing checks does not establish authentication or authorization.
  • Missing exp or nbf claims are not checked. Blank expected issuer or audience skips those checks. Times use this device's clock.
  • A JWT file or pasted text is limited to 1 MiB; a verification key is limited to 20,000 UTF-16 code units. Files and input stay in the browser, and downloads do not overwrite source files.
Open Inspect and verify JWT →
HMAC-SHA256 generatorCalculate a SHA-256 HMAC and compare it with a supplied signature in Hex, Base64 or Base64URL.

Calculate an HMAC-SHA256 from exact UTF-8 message text and a UTF-8 key. Choose Hex, Base64 or Base64URL, then optionally compare a known signature. The key is hidden while you work and cleared when you leave this tool.

Steps

  1. Enter the exact message text and a UTF-8 key. Use the show control only when you need to check the key.
  2. Choose Hex, Base64 or Base64URL to match the format expected by your integration.
  3. Optionally paste a known signature in that format; calculate and check the match result.
  4. Copy or download the selected signature.

Capabilities and limits

  • The message and key are UTF-8 text. Even one different space or line ending changes the result; pasted text cannot guarantee the original bytes of a live HTTP request. Empty messages are valid, but a key is required.
  • Hex comparison accepts an optional sha256= prefix. Base64 signatures are padded and Base64URL signatures are unpadded. A local match is a debugging aid, not server-side sender verification or a full JWT/Webhook validator.
  • Processing stays in your browser. The key is not included in results or retained in the site workspace after leaving this tool. Message text is limited to 1 MiB; the key and comparison signature share the tool parameter limit.
Open HMAC-SHA256 generator →
Base32 encoder / decoderEncode text or any file as RFC 4648 Base32, or decode Base32 to the original bytes.

Encode UTF-8 text or raw file bytes to canonical RFC 4648 Base32. Decode valid Base32 to exact bytes, with a text preview when the result is readable UTF-8.

Steps

  1. Choose Encode or Decode, then choose pasted text or a file.
  2. For encoding, enter UTF-8 text or select any file. For decoding, paste Base32 or select a UTF-8 .txt, .b32 or .base32 file.
  3. Convert, inspect the bytes and preview, then copy the full text or download the output file.

Available options

Mode
encode · decode

Capabilities and limits

  • Paste up to 1 MiB of text or select one file up to 10 MiB. Encoded file input must be UTF-8 text.
  • Uses RFC 4648 Base32 (A–Z, 2–7). Lowercase and missing padding are accepted; invalid characters, padding and nonzero pad bits are rejected. Base32hex and Crockford variants are not supported.
  • Conversion runs in your browser. Base32 is not encryption.
Open Base32 encoder / decoder →
Hex and text converterEncode text or file bytes as hex and Base64 of the same bytes, or decode plain hex to exact bytes.

Convert UTF-8 text or any file into lowercase hexadecimal byte pairs and Base64 of the same bytes. Decode plain hex back to exact bytes, with a text preview when the result is readable UTF-8.

Steps

  1. Choose Encode or Decode, then choose pasted text or a file.
  2. For encoding, enter UTF-8 text or select any file. For decoding, paste plain hex byte pairs or choose a UTF-8 .txt or .hex file.
  3. Convert, inspect the hex and same-byte Base64, then copy or download either result; decoding also preserves the original bytes.

Available options

Mode
encode · decode

Capabilities and limits

  • Paste up to 1 MiB of text or select one file up to 10 MiB. Hex input files must be UTF-8 text.
  • Use an even number of hex digits (0–9, A–F). ASCII whitespace is ignored. Offset columns, 0x prefixes and Intel HEX records are not parsed.
  • Conversion runs in your browser. Hex encoding is not encryption.
Open Hex and text converter →
Binary and text converterEncode UTF-8 text or file bytes as eight-bit groups or a MATLAB numeric row vector assignment; decode bit text to exact bytes.

Convert UTF-8 text or any file into eight-bit byte groups or a MATLAB assignment that creates one numeric 0/1 row vector. Decode bit text back to exact bytes.

Steps

  1. Choose Encode or Decode. For encoding, select byte groups or a MATLAB numeric row vector assignment.
  2. For encoding, enter UTF-8 text or select any file. For decoding, paste 0/1 bit text or choose a UTF-8 .txt or .bits file.
  3. Convert, preview, then copy or download the full bit text or MATLAB .m file; decoding preserves exact bytes.

Available options

Mode
encode · decode
Output format
Space-separated bytes · MATLAB numeric row vector

Capabilities and limits

  • Paste up to 1 MiB of text or select one file up to 2 MiB. Bit-text files must be UTF-8 text.
  • Use only 0 and 1, with a multiple of eight bits. ASCII whitespace is ignored. Prefixes, offsets and partial bytes are not parsed.
  • MATLAB output represents UTF-8 bytes, so non-ASCII text may differ from MATLAB character-code bits. Conversion runs in your browser; binary encoding is not encryption.
Open Binary and text converter →
Quoted-printable converterEncode a MIME body as quoted-printable or decode one to exact bytes and readable text.

Encode UTF-8 body text with MIME line breaks, or encode any file from its exact bytes. Decode a quoted-printable body to the original bytes and preview text using UTF-8 or Windows-1252.

Steps

  1. Choose Encode or Decode, then choose pasted body text or a file.
  2. For decoding, paste only the quoted-printable body or select a .txt/.qp file; choose its charset from the MIME Content-Type header for the text preview.
  3. Convert, check the line-break and byte facts, then copy complete text or download the exact decoded bytes.

Available options

Mode
encode · decode

Capabilities and limits

  • Paste up to 1 MiB of text. Choose one file up to 2 MiB for encoding or 7 MiB for decoding; a decode file must contain ASCII quoted-printable body text.
  • This handles one MIME body part, not a whole .eml message, multipart boundaries or RFC 2047 encoded headers. Invalid escapes are rejected; overlong source lines and transport padding are reported.
  • Text encoding normalizes meaningful line breaks to CRLF. File encoding preserves original bytes. Decoded bytes are always downloadable; charset selection affects only the readable preview.
Open Quoted-printable converter →
SAML response inspectorDecode a SAML 2.0 response locally and inspect SSO status, audience, recipient, NameID and attributes.

Paste a SAMLResponse field, Base64 payload or SAML 2.0 XML to inspect the fields used when troubleshooting SSO. Compare the response and assertion values with your IdP and service provider configuration. Everything stays in this browser.

Steps

  1. In your browser network panel, copy the SAMLResponse value from the SSO POST, or use a SAML 2.0 XML file.
  2. Paste the Base64 value, SAMLResponse= field or XML; alternatively choose a UTF-8 .xml or .txt file. The input check identifies the document before you run.
  3. Select “Inspect response” and compare Status, Issuer, Destination, InResponseTo, audience, recipient, NameID and attributes. Save the JSON only if needed.

Capabilities and limits

  • This is a structural inspector. It does not verify XML signatures, certificates, issuer trust, identity claims or assertion validity.
  • Encrypted assertions cannot be read without a decryption key; the tool only reports their count.
  • The browser processes your input locally. The source and JSON result may contain sensitive identities and attributes. Clear or close the tab when finished.
Open SAML response inspector →
Password generatorGenerate random passwords that fit a site’s length and character rules.

Generate passwords in your browser. Choose a length and character groups, narrow the allowed symbols if a site requires it, then copy a result into your password manager.

Steps

  1. Choose length, quantity and the allowed character groups. Each enabled group appears at least once.
  2. If the site restricts symbols, edit the allowed symbols or switch to a custom ASCII alphabet.
  3. Generate, copy one password and save it securely. The results are cleared when you leave this tool or refresh.

Available options

Character selection
Character groups · Custom alphabet
Password length
24
How many passwords
1
Uppercase A–Z
On by default
Lowercase a–z
On by default
Digits 0–9
On by default
Symbols
On by default
Allowed symbols
!@#$%&*?-_

Enter 1–32 distinct ASCII punctuation characters accepted by the site.

Avoid similar-looking characters (O, 0, I, l, 1)
Off by default
Custom ASCII alphabet
ABCDEFGHJKLMNPQRSTUVWXYZabcdefghijkmnopqrstuvwxyz23456789!@#$%&*

Use 2–94 distinct printable ASCII characters; no spaces.

Capabilities and limits

  • Uses browser cryptographic randomness. Choose a different password for each account and save it in a password manager.
  • Length 8–256; up to 100 passwords at once. A destination service may have additional rules.
Open Password generator →
Passphrase generatorCreate a six-word or longer EFF passphrase for a password manager, disk encryption, or an account that accepts long passwords.

Create a passphrase from independently selected EFF long-list words. Six words is the default for a password manager or disk encryption. Check the destination’s length and character rules before using it.

Steps

  1. Choose 6–20 words and a single printable separator, or leave it empty to join the words. Enable capitalization or one digit only if the destination requires it.
  2. Generate and reveal the phrase only when you need to inspect it. Check its character length against the destination limit.
  3. Copy the phrase into a password manager or secure setup screen. Save a recovery copy if the destination requires one.

Available options

Number of words
6

Six random words by default; increase if your threat model allows the extra length.

Separator character
-

Use one printable ASCII character (-, _, . or space), or leave empty to join words.

Capitalize each word
Off by default
Add one random digit
Off by default

Capabilities and limits

  • Uses all 7,776 words from the EFF Long Wordlist (Joseph Bonneau / EFF, CC BY 3.0 US); each word is drawn independently, so repeats are possible.
  • Uses browser cryptographic randomness. Capitalization and one digit help meet site rules; they are not a substitute for more random words.
  • The generated phrase is a secret. It is hidden at first and cleared from this page on navigation or refresh; clipboard and downloaded TXT remain under your control.
Open Passphrase generator →
SRI hash generatorCalculate SHA-256, SHA-384 or SHA-512 SRI from local file bytes or UTF-8 text, then copy an integrity value or HTML tag.

Generate a Subresource Integrity value from the exact bytes of a local JavaScript or CSS file. You can also paste UTF-8 text. Add a resource URL to build a script or stylesheet tag; this tool does not fetch the URL.

Steps

  1. Choose a local file or switch to pasted text. For a deployed asset, use the exact built file.
  2. Choose SHA-256, SHA-384 or SHA-512. Optionally enter an HTTPS URL or site path and select script or stylesheet.
  3. Calculate, check the hashed byte count, then copy the integrity value or HTML tag. Recalculate after changes.

Available options

Resource source
Local file · Paste text
Algorithm
SHA-256 · SHA-384 · SHA-512
Resource URL (optional)
Enter as needed

HTTPS URL or /site-path. Used only to build a tag; never fetched.

HTML resource type
JavaScript <script> · CSS <link>

Capabilities and limits

  • Hash one local file (up to 10 MB) or pasted UTF-8 text (up to 1 MB) in your browser. Text input uses LF line endings. The optional URL is used only in the generated tag.
  • SRI works only when the deployed resource bytes match the hashed input. Cross-origin resources require CORS and the crossorigin attribute.
Open SRI hash generator →
SSH public-key fingerprintCalculate a SHA256 fingerprint from an OpenSSH RSA or Ed25519 public-key blob and validate its wire structure.

Calculate the full SHA256 fingerprint of one OpenSSH RSA or Ed25519 public key. Paste a .pub key, then optionally compare it with a trusted SHA256 fingerprint displayed elsewhere.

Steps

  1. Paste one OpenSSH public key beginning with ssh-ed25519 or ssh-rsa, or choose a .pub file.
  2. Optionally enter the complete SHA256: fingerprint shown by a trusted service.
  3. Inspect the full calculated fingerprint and exact match result; a matching comment alone proves nothing.

Available options

Expected SHA256 fingerprint (optional)
Enter as needed

Paste the complete SHA256: value from a trusted service. Blank skips the comparison.

Capabilities and limits

  • One OpenSSH RSA or Ed25519 public key per run. Private keys, SSH certificates, other algorithms and multiline key lists are rejected. Comments are excluded from the fingerprint.
  • The optional expected value must be a complete, unpadded SHA256: fingerprint from a trusted source. This page cannot verify GitHub account ownership or SSH access.
  • Public-key input stays in the browser. A pasted key or one UTF-8 .pub/.txt file is limited to 1 MiB. Outputs do not overwrite original files.
Open SSH public-key fingerprint →
File checksum manifestsGenerate SHA256SUMS for a batch or verify selected files against a manifest, reporting missing, changed and unlisted files.

Generate a SHA256SUMS file for up to 20 selected local files, or compare selected files with a trusted SHA256SUMS manifest. The result identifies matching, changed, missing and unlisted names.

Steps

  1. Choose up to 20 local files and generate a downloadable SHA256SUMS manifest.
  2. To verify, select the received files, switch the task to Verify, then paste a trusted previous manifest. Choose complete-manifest or selected-files verification scope.
  3. Review matched, changed, missing and unlisted names separately; download the full JSON report if needed.

Available options

Task
Generate manifest · Verify manifest
Verification scope (verify mode)
Complete manifest (missing fails) · Selected files (report missing entries)

Capabilities and limits

  • Select up to 20 files, 30 MiB each and 80 MiB total. Files are selected individually; folders and recursive scans are not supported. Exact filenames must be unique and cannot contain path separators.
  • The manifest uses the GNU SHA256SUMS form: 64 hexadecimal digits, two spaces, then the exact filename. Verification accepts a space or * marker. A checksum detects changes but does not authenticate the manifest publisher. Verification accepts one safe leading ./ and matches the resulting exact basename; nested paths, parent traversal, drive prefixes, backslashes, NUL and duplicate normalized names are rejected.
  • Original file bytes stay in the browser. A pasted verification manifest is limited to 1 MiB and 1,000 entries; outputs do not overwrite original files.
  • Complete-manifest policy requires every entry present and matching. Selected-files policy permits absent entries while retaining their names and count; scopePassed applies only to that scope. verified always means the complete manifest matched, and never verifies unselected files.
Open File checksum manifests →

Tools used in this article

Base64 encode / decode →Encode or decode a snippet in a click.URL encode / decode →Make those encoded characters readable again.HTML entities →Convert between HTML entities and readable characters.Unicode escape →Convert Unicode escapes into readable text and back.SHA-256 checksum →Calculate a SHA-256 checksum for text or a file.Inspect and verify JWT →Inspect complete JWT header and claims, or verify HS256 / RS256 with a separately supplied trusted key.HMAC-SHA256 generator →Calculate a SHA-256 HMAC and compare it with a supplied signature in Hex, Base64 or Base64URL.Base32 encoder / decoder →Encode text or any file as RFC 4648 Base32, or decode Base32 to the original bytes.Hex and text converter →Encode text or file bytes as hex and Base64 of the same bytes, or decode plain hex to exact bytes.Binary and text converter →Encode UTF-8 text or file bytes as eight-bit groups or a MATLAB numeric row vector assignment; decode bit text to exact bytes.Quoted-printable converter →Encode a MIME body as quoted-printable or decode one to exact bytes and readable text.SAML response inspector →Decode a SAML 2.0 response locally and inspect SSO status, audience, recipient, NameID and attributes.Password generator →Generate random passwords that fit a site’s length and character rules.Passphrase generator →Create a six-word or longer EFF passphrase for a password manager, disk encryption, or an account that accepts long passwords.SRI hash generator →Calculate SHA-256, SHA-384 or SHA-512 SRI from local file bytes or UTF-8 text, then copy an integrity value or HTML tag.SSH public-key fingerprint →Calculate a SHA256 fingerprint from an OpenSSH RSA or Ed25519 public-key blob and validate its wire structure.File checksum manifests →Generate SHA256SUMS for a batch or verify selected files against a manifest, reporting missing, changed and unlisted files.