<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Thien from IO Tools</title>
    <description>The latest articles on DEV Community by Thien from IO Tools (@iotools_thien).</description>
    <link>https://dev.to/iotools_thien</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4174288%2F3a52d416-06b4-45b8-ad0b-7a2f80d90d8f.png</url>
      <title>DEV Community: Thien from IO Tools</title>
      <link>https://dev.to/iotools_thien</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/iotools_thien"/>
    <language>en</language>
    <item>
      <title>12 free browser-only dev tools (JSON, YAML, JWT, regex, hashes) that don't upload your data</title>
      <dc:creator>Thien from IO Tools</dc:creator>
      <pubDate>Fri, 09 Oct 2026 22:21:09 +0000</pubDate>
      <link>https://dev.to/iotools_thien/12-free-browser-only-dev-tools-json-yaml-jwt-regex-hashes-that-dont-upload-your-data-18o1</link>
      <guid>https://dev.to/iotools_thien/12-free-browser-only-dev-tools-json-yaml-jwt-regex-hashes-that-dont-upload-your-data-18o1</guid>
      <description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Disclosure:&lt;/strong&gt; I'm part of the team behind IO Tools (iotools.cloud), the site every link below points to. They're all free and need no account. I've stuck to tools whose pages say processing happens in your browser.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;We've all done it: an API response, a JWT or a config file needs a quick look, so you paste it into the first "online formatter" you find. That token might be a live production credential, and that config might hold a connection string.&lt;/p&gt;

&lt;p&gt;The fix is simple: use tools that do the work client-side, so the data never leaves your machine. Here are 12 I reach for every week, in roughly the order they come up while debugging.&lt;/p&gt;

&lt;h2&gt;
  
  
  1. JSON Formatter: make a minified blob readable
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://iotools.cloud/tool/json-formatter/" rel="noopener noreferrer"&gt;https://iotools.cloud/tool/json-formatter/&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Paste a one-line API response and get it indented, validated and (optionally) with sorted keys, which is handy for diffing two responses. The page says parsing and formatting run entirely in your browser, so it's safe for responses you wouldn't paste into a random server.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Tip:&lt;/strong&gt; sort the keys before you diff. Half the "differences" between two JSON payloads are just key order.&lt;/p&gt;

&lt;h2&gt;
  
  
  2. JSON Compare: what actually changed?
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://iotools.cloud/tool/json-compare/" rel="noopener noreferrer"&gt;https://iotools.cloud/tool/json-compare/&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Diffing JSON as text is noisy. This tool compares by structure (objects by key, arrays by index) and lists every added, removed and changed value by its key path. Great for "it worked yesterday" moments.&lt;/p&gt;

&lt;h2&gt;
  
  
  3. JSONPath Tester: pull one value out of a huge payload
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://iotools.cloud/tool/jsonpath-tester/" rel="noopener noreferrer"&gt;https://iotools.cloud/tool/jsonpath-tester/&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;When a response is 4,000 lines and you need &lt;code&gt;$.data.items[*].id&lt;/code&gt;, test the expression here first. It supports wildcards, recursive descent, slices and filter expressions, so you can check your path before it goes into code or a &lt;code&gt;jq&lt;/code&gt; script.&lt;/p&gt;

&lt;h2&gt;
  
  
  4. JSON to TypeScript: types from a real response
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://iotools.cloud/tool/json-to-typescript-converter/" rel="noopener noreferrer"&gt;https://iotools.cloud/tool/json-to-typescript-converter/&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Paste a sample payload and get interfaces back, nested types included. It's a much faster starting point than typing them by hand. Just tighten the optional fields afterwards.&lt;/p&gt;

&lt;h2&gt;
  
  
  5. JSON ↔ YAML converters: for configs and CI files
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;JSON to YAML: &lt;a href="https://iotools.cloud/tool/json-to-yaml-converter/" rel="noopener noreferrer"&gt;https://iotools.cloud/tool/json-to-yaml-converter/&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;YAML to JSON: &lt;a href="https://iotools.cloud/tool/yaml-to-json-converter/" rel="noopener noreferrer"&gt;https://iotools.cloud/tool/yaml-to-json-converter/&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Kubernetes manifests, GitHub Actions and OpenAPI specs all bounce between the two formats. The JSON→YAML converter also tolerates JSON5-style comments and trailing commas, which saves a cleanup step.&lt;/p&gt;

&lt;h2&gt;
  
  
  6. YAML Validator: find the indentation that broke the deploy
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://iotools.cloud/tool/yaml-validator/" rel="noopener noreferrer"&gt;https://iotools.cloud/tool/yaml-validator/&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;It gives you the line and column of the error plus a structure summary (document count, top-level type, key counts). That's quicker than waiting for CI to fail.&lt;/p&gt;

&lt;h2&gt;
  
  
  7. JWT Decoder: read the token before you regenerate it
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://iotools.cloud/tool/jwt-decode/" rel="noopener noreferrer"&gt;https://iotools.cloud/tool/jwt-decode/&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Most 401s come down to &lt;code&gt;exp&lt;/code&gt;, &lt;code&gt;aud&lt;/code&gt; or &lt;code&gt;iss&lt;/code&gt;. This decodes the header and payload and shows &lt;code&gt;iat&lt;/code&gt;/&lt;code&gt;nbf&lt;/code&gt;/&lt;code&gt;exp&lt;/code&gt; as readable UTC times. It only inspects the token (it doesn't verify the signature), and the page says the token never leaves your browser.&lt;/p&gt;

&lt;p&gt;If you just want a yes/no, there's also a JWT Expiry Checker: &lt;a href="https://iotools.cloud/tool/jwt-expiry-checker/" rel="noopener noreferrer"&gt;https://iotools.cloud/tool/jwt-expiry-checker/&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  8. Regex Tester (and Explainer): before it ships
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Tester: &lt;a href="https://iotools.cloud/tool/regex-tester/" rel="noopener noreferrer"&gt;https://iotools.cloud/tool/regex-tester/&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Explainer: &lt;a href="https://iotools.cloud/tool/regex-explainer/" rel="noopener noreferrer"&gt;https://iotools.cloud/tool/regex-explainer/&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The tester runs matches with the same JavaScript engine your front end uses, so there are no "works in PCRE, fails in JS" surprises. The explainer breaks a pattern down token by token. Run any regex you inherited from someone else through it first.&lt;/p&gt;

&lt;h2&gt;
  
  
  9. Hash Generator: check a checksum or webhook payload
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://iotools.cloud/tool/hash-generator/" rel="noopener noreferrer"&gt;https://iotools.cloud/tool/hash-generator/&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;MD5, SHA-1, SHA-256, SHA-512 and friends, computed locally with the open-source &lt;code&gt;@noble/hashes&lt;/code&gt; library. It's useful for checking downloads and debugging signature mismatches. (The page itself reminds you to use Argon2 or bcrypt for passwords, not a fast hash.)&lt;/p&gt;

&lt;h2&gt;
  
  
  10. Base64 Decode + URL Encoder/Decoder: the encoding pair
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Base64 decode: &lt;a href="https://iotools.cloud/tool/base64-decode/" rel="noopener noreferrer"&gt;https://iotools.cloud/tool/base64-decode/&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;URL encode/decode: &lt;a href="https://iotools.cloud/tool/url-encoder-decoder/" rel="noopener noreferrer"&gt;https://iotools.cloud/tool/url-encoder-decoder/&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;If an auth header, a webhook body or a query string looks like gibberish, it's usually one of these two, and sometimes both. There's even a ready-made chain for that: &lt;a href="https://iotools.cloud/chains/base64-encode-then-url-encode/" rel="noopener noreferrer"&gt;https://iotools.cloud/chains/base64-encode-then-url-encode/&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  11. Unix Timestamp Converter: is that 1728518400 in UTC or local?
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://iotools.cloud/tool/unix-timestamp-converter/" rel="noopener noreferrer"&gt;https://iotools.cloud/tool/unix-timestamp-converter/&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;It converts both ways, handles seconds and milliseconds, and the FAQ confirms nothing you paste leaves your device. This is the tool I use most for reading logs.&lt;/p&gt;

&lt;h2&gt;
  
  
  12. Cron Expression Explainer: what does &lt;code&gt;0 */6 * * 1-5&lt;/code&gt; actually mean?
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://iotools.cloud/tool/cron-expression-explainer/" rel="noopener noreferrer"&gt;https://iotools.cloud/tool/cron-expression-explainer/&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Get a plain-English description plus the next run times. It's ideal for reviewing someone's scheduler PR without counting asterisks.&lt;/p&gt;

&lt;h2&gt;
  
  
  Bonus: UUID Generator
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://iotools.cloud/tool/uuid-generator/" rel="noopener noreferrer"&gt;https://iotools.cloud/tool/uuid-generator/&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;v4, v7 (time-ordered, great for database keys) and more, in bulk, generated in your browser with a cryptographic RNG.&lt;/p&gt;




&lt;h2&gt;
  
  
  A quick way to check if a tool is client-side
&lt;/h2&gt;

&lt;p&gt;Whichever site you use, open DevTools → Network, clear the log, paste your input and click the button. If no request goes out carrying your data, it's client-side. It takes ten seconds and is worth doing before you paste anything sensitive.&lt;/p&gt;

&lt;h2&gt;
  
  
  Grab them all in one place
&lt;/h2&gt;

&lt;p&gt;If you want these in a side panel rather than a tab, the IO Tools browser extension puts 50 of them in Chrome, Edge, Firefox or Opera with no network calls: &lt;a href="https://iotools.cloud/extension/" rel="noopener noreferrer"&gt;https://iotools.cloud/extension/&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;There's also a curated JSON workflow here: &lt;a href="https://iotools.cloud/collections/work-with-json-data/" rel="noopener noreferrer"&gt;https://iotools.cloud/collections/work-with-json-data/&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;What's in your own "paste it somewhere safe" toolkit? I'd love suggestions for tools we're missing. And again, full disclosure: I'm on the IO Tools team, so feedback (including "this one's broken") goes straight to the people who can fix it.&lt;/p&gt;

</description>
      <category>showdev</category>
      <category>webdev</category>
      <category>tools</category>
      <category>productivity</category>
    </item>
  </channel>
</rss>
