developer-tools
65+ free in-browser developer tools (JSON, Base64, JWT, hash, regex…) callable over MCP.
- 1.0.1
- Version
- remote
- Transport
- 77
- Tools
Security review
Review passedReviewed Jan 1, 2000.
- tools: 77 tools scanned
- metadata: scanned
No findings.
Tools (77)
json
Format, minify, validate and convert JSON.. Operations: "format" — Pretty-print JSON with a configurable indent.; "minify" — Strip all insignificant whitespace from JSON.; "validate" — Check whether the input is valid JSON, reporting the error location.; "repair" — Best-effort repair of common JSON mistakes (trailing commas, single quotes, unquoted keys).. Call with "operation" plus "input" (and "options" where relevant).
base64
Encode and decode text in Base64, Base64URL, Base32, Base58, Base85 and hex.. Operations: "encode" — Encode text into the chosen format.; "decode" — Decode text from the chosen format back to plain text.. Call with "operation" plus "input" (and "options" where relevant).
url
Parse, validate and normalize URLs.. Operations: "parse" — Break a URL into its component parts.; "validate" — Validate a URL and run basic security/heuristic checks.; "normalize" — Normalize a URL (drop default ports, sort query params, strip trailing slash).. Call with "operation" plus "input" (and "options" where relevant).
url-encode
Percent-encode and decode URL strings.. Operations: "encode" — Percent-encode a string.; "decode" — Decode a percent-encoded string.. Call with "operation" plus "input" (and "options" where relevant).
jwt
Decode JWT header and payload (no signature verification).. Operations: "decode" — Decode a JWT into its header, payload and signature.. Call with "operation" plus "input" (and "options" where relevant).
html-entity
Encode and decode HTML entities (named, decimal, hex).. Operations: "encode" — Encode text into HTML entities.; "decode" — Decode HTML entities back to plain text.. Call with "operation" plus "input" (and "options" where relevant).
hash
Compute MD5, SHA-1/256/384/512, CRC32 and HMAC digests.. Operations: "hash" — Hash text with the chosen algorithm.; "hmac" — Compute an HMAC digest (SHA algorithms only).. Call with "operation" plus "input" (and "options" where relevant).
uuid
Generate and inspect UUIDs.. Operations: "v4" — Generate one or more random (v4) UUIDs.; "v3" — Generate a name-based (v3 / MD5) UUID.; "parse" — Parse a UUID and report its version, variant and (where present) timestamp.. Call with "operation" plus "input" (and "options" where relevant).
password
Generate strong random passwords and estimate their strength.. Operations: "generate" — Generate a cryptographically random password.; "strength" — Estimate the entropy and strength bucket of a password.. Call with "operation" plus "input" (and "options" where relevant).
random
Generate cryptographically secure random strings.. Operations: "generate" — Generate a secure random string from a chosen pattern.. Call with "operation" plus "input" (and "options" where relevant).
case
Convert text between camelCase, snake_case, kebab-case and more.. Operations: "convert" — Convert text to a single chosen case.; "all" — Return every supported case transform at once.. Call with "operation" plus "input" (and "options" where relevant).
slugify
Turn arbitrary text into a clean, URL-safe slug.. Operations: "slugify" — Generate a URL slug from text.. Call with "operation" plus "input" (and "options" where relevant).
yaml-json
Convert between YAML and JSON.. Operations: "yaml-to-json" — Convert YAML to JSON.; "json-to-yaml" — Convert JSON to YAML.. Call with "operation" plus "input" (and "options" where relevant).
json-ts
Generate TypeScript type declarations from a JSON sample.. Operations: "generate" — Infer TypeScript interfaces/types from JSON.. Call with "operation" plus "input" (and "options" where relevant).
json-csv
Convert between JSON and CSV.. Operations: "json-to-csv" — Convert a JSON array/object to CSV.; "csv-to-json" — Convert CSV to a JSON array.. Call with "operation" plus "input" (and "options" where relevant).
color
Convert colors between HEX, RGB, HSL, HSV and CMYK.. Operations: "convert" — Convert a HEX color to every supported color space.; "palette" — Generate a color harmony palette from a base color.. Call with "operation" plus "input" (and "options" where relevant).
number-base
Convert numbers between binary, octal, decimal and hex.. Operations: "convert" — Convert a number from one base to all supported bases.. Call with "operation" plus "input" (and "options" where relevant).
chmod
Convert between octal and symbolic Unix file permissions.. Operations: "octal-to-symbolic" — Convert octal permissions (e.g. "755") to a symbolic string and description.; "symbolic-to-octal" — Convert a symbolic permission string (e.g. "rwxr-xr-x") to octal.. Call with "operation" plus "input" (and "options" where relevant).
http-status
Look up and search HTTP status codes.. Operations: "lookup" — Look up a single status code by number.; "search" — Search status codes by number, name or description.. Call with "operation" plus "input" (and "options" where relevant).
css-minify
Minify or beautify CSS.. Operations: "minify" — Minify CSS (strip comments and whitespace).; "beautify" — Beautify CSS (one declaration per line, indented).. Call with "operation" plus "input" (and "options" where relevant).
curl-converter
Convert a curl command into fetch / Python / Node snippets.. Operations: "convert" — Parse a curl command and generate code snippets.. Call with "operation" plus "input" (and "options" where relevant).
sql
Format and minify SQL.. Operations: "beautify" — Beautify SQL with newlines before clauses.; "minify" — Minify SQL to a single line.. Call with "operation" plus "input" (and "options" where relevant).
xml
Pretty-print or minify already-serialized XML, and highlight it.. Operations: "format" — Pretty-print XML with the chosen indent (server-safe string transform).; "minify" — Collapse whitespace between XML tags (server-safe string transform).. Call with "operation" plus "input" (and "options" where relevant).
html
Format, minify and validate HTML.. Operations: "format" — Pretty-print HTML.; "minify" — Minify HTML (strip comments and collapse whitespace).; "validate" — Check HTML for unclosed/mismatched tags.. Call with "operation" plus "input" (and "options" where relevant).
markdown
Render Markdown to HTML, build a TOC and compute statistics.. Operations: "render" — Render GitHub-flavored Markdown to sanitized HTML.; "toc" — Extract a table of contents from Markdown headers.; "stats" — Compute document statistics for Markdown/plain text.. Call with "operation" plus "input" (and "options" where relevant).
timestamp
Convert and inspect Unix timestamps and dates.. Operations: "to-date" — Convert a Unix timestamp (seconds) to a full date breakdown.; "parse-date" — Auto-detect and parse a date/timestamp string.. Call with "operation" plus "input" (and "options" where relevant).
cron
Describe cron expressions and compute upcoming run times.. Operations: "describe" — Produce a human-readable description of a cron expression.; "next-runs" — Compute the next N run times for a cron expression.. Call with "operation" plus "input" (and "options" where relevant).
regex
Test a regex against a string and apply replacements.. Operations: "test" — Find all matches of a regex pattern in a test string.; "replace" — Replace regex matches in a string.. Call with "operation" plus "input" (and "options" where relevant).
lorem
Generate placeholder text in several styles.. Operations: "generate" — Generate lorem ipsum (or themed) placeholder text.. Call with "operation" plus "input" (and "options" where relevant).
word-count
Count words/characters and compute readability statistics.. Operations: "count" — Compute basic text statistics (words, characters, sentences, etc.).; "readability" — Compute readability scores (Flesch, SMOG, Coleman-Liau).; "keywords" — Compute keyword density for the text.. Call with "operation" plus "input" (and "options" where relevant).
diff
Compute a line-by-line diff between two texts.. Operations: "compare" — Diff two texts and return the lines plus statistics.; "unified" — Produce a unified-diff text between two inputs.. Call with "operation" plus "input" (and "options" where relevant).
bcrypt
Hash and verify passwords with bcrypt.. Operations: "hash" — Hash a password with bcrypt at the given cost.; "verify" — Verify a plaintext password against a bcrypt hash.. Call with "operation" plus "input" (and "options" where relevant).
wifi-qr
Build the standard WIFI: payload string for a WiFi QR code.. Operations: "payload" — Build the WIFI: payload string a phone scans to auto-join a network.. Call with "operation" plus "input" (and "options" where relevant).
gitignore
Generate a combined .gitignore from template keys.. Operations: "generate" — Combine one or more template keys into a .gitignore.; "templates" — List the available .gitignore template keys.. Call with "operation" plus "input" (and "options" where relevant).
contrast
Check WCAG contrast between a foreground and background color.. Operations: "check" — Compute the contrast ratio and WCAG pass/fail for a color pair.; "best-text" — Pick black or white text for the best contrast on a background.. Call with "operation" plus "input" (and "options" where relevant).
image-base64
Build and parse base64 data URIs and embed snippets.. Operations: "build-snippets" — Build HTML/CSS/Markdown snippets from an existing data URI.. Call with "operation" plus "input" (and "options" where relevant).
json-schema
Infer a draft-07 JSON Schema from sample JSON.. Operations: "generate" — Infer a draft-07 JSON Schema from sample JSON. Call with "operation" plus "input" (and "options" where relevant).
cidr
Parse a CIDR block into its network, broadcast and host range.. Operations: "calculate" — Calculate the network, broadcast, mask and host range for a CIDR block.. Call with "operation" plus "input" (and "options" where relevant).
user-agent
Parse a User-Agent string into browser, engine, OS and device.. Operations: "parse" — Parse a User-Agent string into browser, engine, OS and device details.. Call with "operation" plus "input" (and "options" where relevant).
color-palette
Generate harmony, shade and tint palettes from a base HEX color.. Operations: "generate" — Generate harmony, shade and tint palettes from a base HEX color.. Call with "operation" plus "input" (and "options" where relevant).
password-strength
Analyze a password and estimate its entropy, strength and crack time.. Operations: "analyze" — Analyze a password and estimate its entropy, strength and crack time.. Call with "operation" plus "input" (and "options" where relevant).
jsonpath
Query a JSON document with a JSONPath expression.. Operations: "query" — Evaluate a JSONPath expression against a JSON document.. Call with "operation" plus "input" (and "options" where relevant).
totp
Generate a time-based one-time password (TOTP) from a base32 secret.. Operations: "generate" — Generate the current TOTP code for a base32 secret.. Call with "operation" plus "input" (and "options" where relevant).
data-size
Parse a data size and convert it to bytes plus decimal and binary units.. Operations: "convert" — Parse a data size and convert it to bytes, decimal and binary units.. Call with "operation" plus "input" (and "options" where relevant).
mime
Look up MIME types by file extension or MIME type.. Operations: "lookup" — Search MIME types by extension or MIME type.. Call with "operation" plus "input" (and "options" where relevant).
sort-lines
Sort, reverse, deduplicate and clean up lines of text.. Operations: "process" — Sort, deduplicate and clean lines of text.. Call with "operation" plus "input" (and "options" where relevant).
jwt-encode
Sign a JSON payload into a JWT with an HMAC secret.. Operations: "sign" — Sign a JSON payload into a JWT using an HMAC secret.. Call with "operation" plus "input" (and "options" where relevant).
ulid
Generate a lexicographically sortable ULID.. Operations: "generate" — Generate a new ULID.. Call with "operation" plus "input" (and "options" where relevant).
string-escape
Escape and unescape strings for JSON, JS, HTML, URL and regex.. Operations: "escape" — Escape a string for the chosen context.; "unescape" — Unescape a string from the chosen context.. Call with "operation" plus "input" (and "options" where relevant).
ascii
Convert text to and from character codes in several bases.. Operations: "to-codes" — Convert text to character codes.; "from-codes" — Convert character codes back to text.. Call with "operation" plus "input" (and "options" where relevant).
roman-numeral
Convert between integers and Roman numerals.. Operations: "to-roman" — Convert an integer to a Roman numeral.; "from-roman" — Convert a Roman numeral to an integer.. Call with "operation" plus "input" (and "options" where relevant).
aes-encrypt
Encrypt and decrypt text with AES-GCM using a password.. Operations: "encrypt" — Encrypt plaintext into base64 ciphertext with a password.; "decrypt" — Decrypt base64 ciphertext produced by the encrypt operation.. Call with "operation" plus "input" (and "options" where relevant).
json-diff
Compare two JSON documents and report added, removed and changed values.. Operations: "diff" — Diff two JSON documents by path.. Call with "operation" plus "input" (and "options" where relevant).
morse-code
Translate text to and from Morse code.. Operations: "encode" — Convert text to Morse code.; "decode" — Convert Morse code to text.. Call with "operation" plus "input" (and "options" where relevant).
markdown-table
Convert CSV or TSV rows into a Markdown table.. Operations: "generate" — Build a Markdown table from delimited rows.. Call with "operation" plus "input" (and "options" where relevant).
hmac
Sign a message with HMAC using a secret key and SHA-2 algorithm.. Operations: "sign" — Compute an HMAC signature for a message.. Call with "operation" plus "input" (and "options" where relevant).
css-units
Convert a numeric value between CSS units (px, rem, em, pt, pc, %).. Operations: "convert" — Convert a numeric value from one CSS unit to another.. Call with "operation" plus "input" (and "options" where relevant).
json-xml
Convert between JSON and XML.. Operations: "to-xml" — Convert JSON to XML.; "to-json" — Convert XML to JSON.. Call with "operation" plus "input" (and "options" where relevant).
char-inspector
Break a string into per-character Unicode details.. Operations: "inspect" — Inspect each character of a string (code point, category, bytes).. Call with "operation" plus "input" (and "options" where relevant).
semver
Parse, compare, sort and bump Semantic Versions, and test versions against npm-style ranges.. Operations: "parse" — Parse a SemVer 2.0.0 version into its components.; "compare" — Compare two versions by SemVer precedence (-1, 0 or 1).; "satisfies" — Test whether a version satisfies a range (^, ~, x, hyphen, ||).; "max-satisfying" — Find the highest and lowest versions in a list that satisfy a range.; "explain-range" — Desugar a range into plain comparators (e.g. ^1.2.3 → >=1.2.3 <2.0.0-0).; "sort" — Sort versions by SemVer precedence; invalid entries are listed separately.; "bump" — Increment a version like `npm version <release>`.. Call with "operation" plus "input" (and "options" where relevant).
duration
Convert between ISO 8601 durations, seconds, clock time and human text like "1h30m" or "90 minutes".. Operations: "convert" — Parse any duration (ISO 8601, 1h30m, 90 minutes, 1:30:00, seconds) into every representation.; "to-iso" — Convert any duration to a canonical ISO 8601 duration string.; "humanize" — Render a duration as words ("1 hour 30 minutes") or compact text ("1h 30m").. Call with "operation" plus "input" (and "options" where relevant).
nanoid
Generate NanoIDs or custom-alphabet random IDs with crypto randomness, plus a collision-probability estimate.. Operations: "generate" — Generate one or more random IDs (default: 21-char URL-safe NanoID).; "collision" — Estimate how long until a 1% collision chance for an alphabet size, ID length and rate.. Call with "operation" plus "input" (and "options" where relevant).
base-n
Encode and decode UTF-8 text as Base32 (RFC 4648 + hex), Crockford Base32, Base58 (Bitcoin), Ascii85 or Z85.. Operations: "encode" — Encode UTF-8 text in the chosen scheme.; "decode" — Decode to UTF-8 text (binary payloads are returned as hex).. Call with "operation" plus "input" (and "options" where relevant).
luhn
Validate check digits: Luhn card numbers (with brand), IBAN mod-97, ISBN-10/13 and EAN/UPC barcodes. Format only — nothing is looked up or stored.. Operations: "validate" — Validate a number, auto-detecting its type or using the one you choose.; "check-digit" — Compute the Luhn or GS1 (EAN/UPC) check digit to append to a payload.. Call with "operation" plus "input" (and "options" where relevant).
x509
Decode PEM/DER X.509 certificates: subject, issuer, validity, SANs, key type/size, signature algorithm, extensions and fingerprints.. Operations: "decode" — Decode every certificate in a PEM bundle (or one bare base64 DER).. Call with "operation" plus "input" (and "options" where relevant).
env-json
Convert dotenv files to JSON and back, with dotenv-compatible quoting, escapes, comments, export prefixes and multi-line values, plus validation warnings.. Operations: "to-json" — Parse a .env file into a JSON object (last duplicate wins).; "to-env" — Write a JSON object as .env lines, quoting values only where needed.; "validate" — Lint a .env file: duplicates, invalid names, unterminated quotes, stray # comments.. Call with "operation" plus "input" (and "options" where relevant).
toml-json
Convert TOML 1.0 to JSON and JSON to TOML, reporting anything that cannot round-trip.. Operations: "to-json" — Parse TOML and return pretty-printed JSON.; "to-toml" — Convert a JSON object to TOML (nulls are dropped with a warning).. Call with "operation" plus "input" (and "options" where relevant).
csp
Parse a Content-Security-Policy, explain each directive and flag weaknesses (unsafe-inline, wildcards, missing object-src/base-uri/frame-ancestors…).. Operations: "evaluate" — Parse a CSP header and return its directives and findings by severity.; "harden" — Add the low-risk directives a policy is missing (object-src 'none', base-uri, frame-ancestors, form-action) and return ready-to-paste header, meta, nginx and Apache forms.. Call with "operation" plus "input" (and "options" where relevant).
security-headers
Grade pasted HTTP response headers (HSTS, CSP, nosniff, framing, Referrer-Policy, Permissions-Policy, COOP/COEP/CORP, cookies) A+ to F. Parses text only; never fetches a URL.. Operations: "grade" — Grade a raw header block and explain each check.. Call with "operation" plus "input" (and "options" where relevant).
ipv6
Expand and compress IPv6 addresses (RFC 5952), classify them (link-local, ULA, multicast, documentation…), extract embedded IPv4, do prefix and range maths, and build ip6.arpa names.. Operations: "analyze" — Analyse an address, prefix or range: canonical and expanded forms, type, embedded IPv4, network bounds, reverse DNS.; "compress" — Rewrite each address in its RFC 5952 canonical (shortest) form.; "expand" — Rewrite each address with all eight 4-digit groups.. Call with "operation" plus "input" (and "options" where relevant).
utm
Build campaign URLs with utm_* parameters, parse and lint tagged links, and strip UTM and click-ID tracking parameters.. Operations: "build" — Add UTM parameters to a URL, normalising case and spaces, and lint the result.; "parse" — Split a URL into UTM tags, ad click IDs and other parameters, with warnings.; "strip" — Remove utm_* and click-ID parameters (gclid, fbclid, msclkid…) from a URL.; "batch" — Tag many URLs (one per line) with the same UTM parameters.. Call with "operation" plus "input" (and "options" where relevant).
aspect-ratio
Reduce a ratio or resolution to lowest terms, name the nearest common ratio, solve the missing dimension and write CSS aspect-ratio.. Operations: "analyze" — Reduce a ratio or size (16:9, 1920x1080, 2.39) and return presets, CSS and whole-pixel sizes.; "solve" — Given a ratio and one dimension, compute the other.; "fit" — Largest size at this ratio that fits inside (contain) or covers (cover) a box.. Call with "operation" plus "input" (and "options" where relevant).
html-jsx
Convert HTML or SVG markup to React JSX: className/htmlFor, camelCased SVG attributes, style objects, self-closing tags, JSX comments.. Operations: "convert" — Convert an HTML fragment or document to JSX, with warnings for anything to review.. Call with "operation" plus "input" (and "options" where relevant).
jsonc
Convert JSON5, JSONC (tsconfig, VS Code settings) and relaxed JSON to strict JSON, or reformat them with comments kept, reporting every non-JSON feature used.. Operations: "to-json" — Convert JSON5 / JSONC to strict RFC 8259 JSON.; "format" — Re-print JSON / JSON5 / JSONC tidily as JSONC or JSON5, keeping comments.; "validate" — Check whether text is valid JSON5 and list which non-JSON features it uses.. Call with "operation" plus "input" (and "options" where relevant).
text-cleanup
Find and remove invisible Unicode (zero-width, bidi/Trojan Source, tag-character smuggling), fix line endings, trailing whitespace, tabs and smart quotes, and normalise Unicode.. Operations: "scan" — Report invisible and special characters, hidden tag-character text, unterminated bidi controls, line endings and normalisation.; "clean" — Apply clean-ups and return the text plus counts of every change.. Call with "operation" plus "input" (and "options" where relevant).
date-calc
Days, months and business days between dates, add or subtract durations, ISO week numbers and day of year, and DST-aware elapsed time between local times.. Operations: "diff" — Difference between two dates in years/months/days, total days, weeks and business days.; "add" — Add or subtract a duration ("1y 2m", "-90d", "P2W") or a number of business days.; "info" — Weekday, day of year, ISO week, quarter and leap year for a date (plus Unix time of local midnight).; "elapsed" — Exact elapsed time between two local date-times, following DST in each time zone.. Call with "operation" plus "input" (and "options" where relevant).
svg-data-uri
Minify an SVG and encode it as a compact percent-encoded (or base64) data URI, with background-image and mask-image CSS.. Operations: "encode" — Optimise an SVG and return url-encoded and base64 data URIs, sizes and CSS snippets.; "decode" — Decode a data:image/svg+xml URI (percent-encoded or base64) back to SVG markup.. Call with "operation" plus "input" (and "options" where relevant).