<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: pulkitgovrani</title>
    <description>The latest articles on DEV Community by pulkitgovrani (@pulkitgovrani).</description>
    <link>https://dev.to/pulkitgovrani</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F405919%2F8cab8c52-f8c7-4f58-bbe8-46cc0851e135.png</url>
      <title>DEV Community: pulkitgovrani</title>
      <link>https://dev.to/pulkitgovrani</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/pulkitgovrani"/>
    <language>en</language>
    <item>
      <title>How to Sign a PDF Without Printing It (And What Counts as a Valid Signature)</title>
      <dc:creator>pulkitgovrani</dc:creator>
      <pubDate>Mon, 28 Sep 2026 16:30:00 +0000</pubDate>
      <link>https://dev.to/pulkitgovrani/how-to-sign-a-pdf-without-printing-it-and-what-counts-as-a-valid-signature-33a7</link>
      <guid>https://dev.to/pulkitgovrani/how-to-sign-a-pdf-without-printing-it-and-what-counts-as-a-valid-signature-33a7</guid>
      <description>&lt;p&gt;Printing, signing, and scanning a form is a hassle you can skip. You can sign a PDF on screen in a minute. Whether that signature is enough depends on what the document is, so it helps to know the different kinds.&lt;/p&gt;

&lt;h2&gt;
  
  
  Three kinds of PDF signatures
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Image (drawn or typed) signature: an image of your handwritten signature placed on the page. Quick and common for everyday forms, but it isn't cryptographically tied to you or to the document.&lt;/li&gt;
&lt;li&gt;Electronic signature service: a platform that records who signed, when, and from where, and produces an audit trail.&lt;/li&gt;
&lt;li&gt;Digital (cryptographic) signature: uses a certificate to sign the document's contents, so any later change invalidates it. Used where authenticity and integrity are critical.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  How to add a drawn signature
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;Open the PDF in a signing tool that runs in your browser.&lt;/li&gt;
&lt;li&gt;Draw your signature with a mouse, trackpad, or touchscreen.&lt;/li&gt;
&lt;li&gt;Place it on the correct page and line, then resize it so it looks natural.&lt;/li&gt;
&lt;li&gt;Download the signed copy and check the placement before sending.&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  Is it legally valid?
&lt;/h2&gt;

&lt;p&gt;In many countries, electronic signatures are legally recognized for a wide range of agreements (for example under the ESIGN Act in the United States and eIDAS in the European Union). But rules vary, and some documents, such as certain property, court, or government forms, require stricter signatures, witnesses, or notarization. If the stakes are high, check the requirements with the recipient or a professional. This isn't legal advice.&lt;/p&gt;

&lt;h2&gt;
  
  
  Protect your signature
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Don't share a clean image of your signature publicly; it can be copied.&lt;/li&gt;
&lt;li&gt;Sign a copy, not your only original file.&lt;/li&gt;
&lt;li&gt;Add the date next to the signature if the form requires one.&lt;/li&gt;
&lt;li&gt;Use a tool that processes the file on your device, so the signed document isn't uploaded anywhere.&lt;/li&gt;
&lt;/ul&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;For serious contracts&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;A pasted image proves little on its own. For contracts where disputes are plausible, use a signing service that records an audit trail, or a certificate-based digital signature.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  Frequently asked questions
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Can I sign a PDF for free?
&lt;/h3&gt;

&lt;p&gt;Yes. Browser-based tools let you draw and place a signature at no cost, and many PDF readers include a built-in sign feature too.&lt;/p&gt;

&lt;h3&gt;
  
  
  Is a drawn signature on a PDF legally binding?
&lt;/h3&gt;

&lt;p&gt;Often yes for ordinary agreements, since electronic signatures are widely recognized, but requirements differ by country and document type.&lt;/p&gt;

&lt;h3&gt;
  
  
  What is a digital signature versus an electronic signature?
&lt;/h3&gt;

&lt;p&gt;An electronic signature is any electronic indication of agreement, such as a drawn image. A digital signature uses cryptography and a certificate to bind the signer to the exact document content.&lt;/p&gt;

&lt;h3&gt;
  
  
  Is it safe to upload a document to sign it online?
&lt;/h3&gt;

&lt;p&gt;Only if you trust the service. A tool that works locally in your browser doesn't upload the document at all.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Try it:&lt;/strong&gt; &lt;a href="https://pdf.ilovekit.app/sign" rel="noopener noreferrer"&gt;Sign PDF&lt;/a&gt; — free, runs in your browser, nothing is uploaded.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://ilovekit.app/blog/how-to-sign-a-pdf-without-printing" rel="noopener noreferrer"&gt;ilovekit.app&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>pdf</category>
      <category>webdev</category>
      <category>programming</category>
      <category>tutorial</category>
    </item>
    <item>
      <title>How to Split a PDF Into Separate Pages or Sections</title>
      <dc:creator>pulkitgovrani</dc:creator>
      <pubDate>Mon, 28 Sep 2026 04:30:00 +0000</pubDate>
      <link>https://dev.to/pulkitgovrani/how-to-split-a-pdf-into-separate-pages-or-sections-1nhc</link>
      <guid>https://dev.to/pulkitgovrani/how-to-split-a-pdf-into-separate-pages-or-sections-1nhc</guid>
      <description>&lt;p&gt;Sometimes you don't need a whole 200-page PDF; you need chapter three, or just the signature page. Splitting a PDF lets you break it into smaller files or pull out specific pages to share, print, or archive.&lt;/p&gt;

&lt;h2&gt;
  
  
  Ways to split a PDF
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Every page: one output file per page, useful for scanned batches of separate documents.&lt;/li&gt;
&lt;li&gt;By range: for example pages 1-5 and 6-12 as two files, good for chapters or sections.&lt;/li&gt;
&lt;li&gt;Extract selected pages: keep only the pages you name, such as 2, 7, and 10-12.&lt;/li&gt;
&lt;li&gt;Delete pages instead: remove the pages you don't want and keep the rest.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Step by step
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;Open the PDF in a splitting tool. A visual page picker helps when you don't know the page numbers.&lt;/li&gt;
&lt;li&gt;Choose how to split: by range, by every page, or by selected pages.&lt;/li&gt;
&lt;li&gt;Double-check the page numbers against what you see in the document; the number printed on a page can differ from its position in the file.&lt;/li&gt;
&lt;li&gt;Download the results and open one to confirm it contains what you expected.&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  Things that trip people up
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Printed vs file page numbers: a book with roman-numeral front matter puts printed page 1 at file page 9 or later. Splitting works on file positions.&lt;/li&gt;
&lt;li&gt;Bookmarks and links: internal links may break when their target page ends up in a different file.&lt;/li&gt;
&lt;li&gt;Encrypted PDFs: you generally need to unlock the file with its password first.&lt;/li&gt;
&lt;li&gt;Fillable forms: form fields belong to the pages they sit on and may lose connections to calculations on other pages.&lt;/li&gt;
&lt;/ul&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Sharing a section privately&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;When you send one page from a larger document, make sure other pages (which may contain sensitive data) are not included. Open the extracted file and scroll through it before you share it.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  Splitting locally
&lt;/h2&gt;

&lt;p&gt;Documents you split are often exactly the ones you shouldn't upload: contracts, statements, and IDs. A browser-based splitter processes the file on your own device, so it never leaves your computer.&lt;/p&gt;

&lt;h2&gt;
  
  
  Frequently asked questions
&lt;/h2&gt;

&lt;h3&gt;
  
  
  How do I extract a single page from a PDF?
&lt;/h3&gt;

&lt;p&gt;Use a split or extract tool and specify just that page number. The tool creates a new PDF containing only that page.&lt;/p&gt;

&lt;h3&gt;
  
  
  Will splitting change the quality of my pages?
&lt;/h3&gt;

&lt;p&gt;No. The pages are copied as they are, so text and images keep their quality.&lt;/p&gt;

&lt;h3&gt;
  
  
  Can I split a password-protected PDF?
&lt;/h3&gt;

&lt;p&gt;You usually need to remove the password first, using the password itself, and then split the file.&lt;/p&gt;

&lt;h3&gt;
  
  
  What is the difference between splitting and extracting pages?
&lt;/h3&gt;

&lt;p&gt;Splitting divides a document into several files. Extracting pulls selected pages into one new file. Many tools offer both.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Try it:&lt;/strong&gt; &lt;a href="https://pdf.ilovekit.app/split" rel="noopener noreferrer"&gt;Split PDF&lt;/a&gt; — free, runs in your browser, nothing is uploaded.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://ilovekit.app/blog/how-to-split-a-pdf-into-separate-pages" rel="noopener noreferrer"&gt;ilovekit.app&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>pdf</category>
      <category>webdev</category>
      <category>programming</category>
      <category>tutorial</category>
    </item>
    <item>
      <title>How to Compress a PDF Without Losing Quality</title>
      <dc:creator>pulkitgovrani</dc:creator>
      <pubDate>Sun, 27 Sep 2026 16:30:00 +0000</pubDate>
      <link>https://dev.to/pulkitgovrani/how-to-compress-a-pdf-without-losing-quality-4ooh</link>
      <guid>https://dev.to/pulkitgovrani/how-to-compress-a-pdf-without-losing-quality-4ooh</guid>
      <description>&lt;p&gt;A PDF that is too big to email is one of life's small annoyances. The good news is that most oversized PDFs are large for a few predictable reasons, and you can usually cut the size dramatically without visible damage.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why PDFs get big
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Images: photos and scans dominate the file size. A 300 dpi color scan of an A4 page can be several megabytes.&lt;/li&gt;
&lt;li&gt;Embedded fonts: each font family adds size, especially large ones with many glyphs.&lt;/li&gt;
&lt;li&gt;Uncompressed or duplicated content: some exporters store the same image or resource repeatedly.&lt;/li&gt;
&lt;li&gt;Metadata and edit history: incremental saves can leave old versions of objects inside the file.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  What compression actually does
&lt;/h2&gt;

&lt;p&gt;Compression tools typically combine several techniques: downsampling images to a lower resolution, re-encoding them at a lower JPEG quality, removing unused objects and metadata, and rewriting the file structure more efficiently. Downsampling and recompressing are lossy, so they trade a little detail for a much smaller file. Cleaning up structure is lossless.&lt;/p&gt;

&lt;h2&gt;
  
  
  Choosing a target
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Email or web viewing: images around 96 to 150 dpi are usually fine on screen.&lt;/li&gt;
&lt;li&gt;Standard printing: aim for about 300 dpi, which is where most photos look sharp on paper.&lt;/li&gt;
&lt;li&gt;Text-only documents: they are rarely large; if one is, look for embedded images or fonts.&lt;/li&gt;
&lt;li&gt;Scanned documents: run OCR-aware or black-and-white scanning at 200 to 300 dpi, since color scans of text are wasteful.&lt;/li&gt;
&lt;/ul&gt;

&lt;ol&gt;
&lt;li&gt;Make a copy of the original so you can go back if the result looks too soft.&lt;/li&gt;
&lt;li&gt;Compress, then zoom in on a page with small text or a photo to check legibility.&lt;/li&gt;
&lt;li&gt;If it is still too large, compress more or split the document into parts.&lt;/li&gt;
&lt;li&gt;Compress once only; repeated compression stacks up quality loss.&lt;/li&gt;
&lt;/ol&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Keep the original&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Lossy compression can't be undone. Always keep the uncompressed original, especially for contracts, drawings, or anything you may need to print at full quality later.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  Ways to shrink a PDF before you export it
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Resize photos before placing them in the document instead of after.&lt;/li&gt;
&lt;li&gt;Export from your design or word-processing tool with a 'web' or 'minimum size' preset.&lt;/li&gt;
&lt;li&gt;Avoid embedding many font weights you don't use.&lt;/li&gt;
&lt;li&gt;Scan in grayscale or black and white when color isn't needed.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Frequently asked questions
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Why is my PDF so large?
&lt;/h3&gt;

&lt;p&gt;Usually because of high-resolution images or scans. Embedded fonts and leftover edit data can add to it.&lt;/p&gt;

&lt;h3&gt;
  
  
  Does compressing a PDF reduce quality?
&lt;/h3&gt;

&lt;p&gt;Image downsampling and recompression are lossy, so quality drops a little. Structural cleanup is lossless. Check the result before sending.&lt;/p&gt;

&lt;h3&gt;
  
  
  What is a good size for an emailed PDF?
&lt;/h3&gt;

&lt;p&gt;Many email providers cap attachments around 20 to 25 MB, but staying under a few megabytes is friendlier to recipients.&lt;/p&gt;

&lt;h3&gt;
  
  
  Can I compress a PDF without uploading it?
&lt;/h3&gt;

&lt;p&gt;Yes, with a browser-based compressor that processes the file locally, which keeps sensitive documents private.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Try it:&lt;/strong&gt; &lt;a href="https://pdf.ilovekit.app/compress" rel="noopener noreferrer"&gt;Compress PDF&lt;/a&gt; — free, runs in your browser, nothing is uploaded.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://ilovekit.app/blog/how-to-compress-a-pdf-without-losing-quality" rel="noopener noreferrer"&gt;ilovekit.app&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>pdf</category>
      <category>webdev</category>
      <category>programming</category>
      <category>tutorial</category>
    </item>
    <item>
      <title>How to Merge PDF Files Without Uploading Them Anywhere</title>
      <dc:creator>pulkitgovrani</dc:creator>
      <pubDate>Sun, 27 Sep 2026 04:30:00 +0000</pubDate>
      <link>https://dev.to/pulkitgovrani/how-to-merge-pdf-files-without-uploading-them-anywhere-2bje</link>
      <guid>https://dev.to/pulkitgovrani/how-to-merge-pdf-files-without-uploading-them-anywhere-2bje</guid>
      <description>&lt;p&gt;Merging PDFs is one of the most common document chores: stitching a cover letter to a resume, combining scanned pages into a single file, or bundling invoices for an accountant. Most free merge sites work by uploading your files to a server. For everyday documents that may be fine, but for contracts, IDs, and medical or financial records it is an unnecessary risk.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why merge locally
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Your files never leave your device, so there is nothing to intercept, store, or leak.&lt;/li&gt;
&lt;li&gt;No file-size upload limits imposed by a server, and no waiting on a slow connection.&lt;/li&gt;
&lt;li&gt;It works even with a weak or metered connection once the page has loaded.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  How to merge PDFs, step by step
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;Open a browser-based PDF merger and add your files (drag and drop works in most tools).&lt;/li&gt;
&lt;li&gt;Put the files in the order you want them to appear; the first file's pages come first.&lt;/li&gt;
&lt;li&gt;Check page counts so you know what to expect in the result.&lt;/li&gt;
&lt;li&gt;Merge, then download the combined file and open it to confirm the page order and orientation.&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  What to expect in the merged file
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Bookmarks and outlines: depending on the tool, the original bookmarks may be dropped. If you rely on a table of contents, check the result.&lt;/li&gt;
&lt;li&gt;Form fields: merging documents that contain forms with the same field names can cause them to share values. Flatten forms first if that matters.&lt;/li&gt;
&lt;li&gt;Page sizes: pages keep their own dimensions, so mixing A4 and Letter gives a document with both.&lt;/li&gt;
&lt;li&gt;File size: the result is roughly the sum of the inputs, so you may want to compress it afterwards.&lt;/li&gt;
&lt;li&gt;Password-protected files: remove the password (with the password in hand) before merging.&lt;/li&gt;
&lt;/ul&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Tip: name the output clearly&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Use a descriptive filename with a date, such as 2026-09-application-bundle.pdf. Merged files tend to get sent to other people, and a clear name avoids mix-ups.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  Common problems and fixes
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Pages appear rotated: rotate the source pages before merging, or fix them after with a rotate tool.&lt;/li&gt;
&lt;li&gt;The file is huge: scanned pages are large images. Compress the result, or rescan at a lower resolution.&lt;/li&gt;
&lt;li&gt;Order is wrong: reorder the input list, or reorder pages in the merged output.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Frequently asked questions
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Is it safe to merge PDFs online?
&lt;/h3&gt;

&lt;p&gt;It depends on the tool. Sites that upload your files to a server can store or expose them. A tool that processes files in your browser never sends them anywhere, which is the safer choice for sensitive documents.&lt;/p&gt;

&lt;h3&gt;
  
  
  Does merging PDFs reduce quality?
&lt;/h3&gt;

&lt;p&gt;No. Merging copies the pages into a new file without re-rendering them, so text and images keep their original quality.&lt;/p&gt;

&lt;h3&gt;
  
  
  Can I merge PDFs and images together?
&lt;/h3&gt;

&lt;p&gt;Convert the images to PDF first (or use an images-to-PDF tool), then merge the resulting PDFs.&lt;/p&gt;

&lt;h3&gt;
  
  
  How many PDFs can I merge at once?
&lt;/h3&gt;

&lt;p&gt;There is usually no fixed limit in a browser tool; the practical limit is your device's memory, so very large files may be slow.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Try it:&lt;/strong&gt; &lt;a href="https://pdf.ilovekit.app" rel="noopener noreferrer"&gt;Merge PDFs&lt;/a&gt; — free, runs in your browser, nothing is uploaded.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://ilovekit.app/blog/how-to-merge-pdf-files-without-uploading" rel="noopener noreferrer"&gt;ilovekit.app&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>pdf</category>
      <category>webdev</category>
      <category>productivity</category>
      <category>privacy</category>
    </item>
    <item>
      <title>How to Decode a JWT Safely (Without Sending It to a Server)</title>
      <dc:creator>pulkitgovrani</dc:creator>
      <pubDate>Sat, 26 Sep 2026 07:16:58 +0000</pubDate>
      <link>https://dev.to/pulkitgovrani/how-to-decode-a-jwt-safely-without-sending-it-to-a-server-ki2</link>
      <guid>https://dev.to/pulkitgovrani/how-to-decode-a-jwt-safely-without-sending-it-to-a-server-ki2</guid>
      <description>&lt;p&gt;A JSON Web Token (JWT) looks like an opaque blob, but it is just three Base64URL-encoded pieces joined by dots. Anyone who holds the token can read what's inside; no secret key is needed. That is by design: JWTs are meant to be signed, not hidden. It is also exactly why you should care where you decode one.&lt;/p&gt;

&lt;h2&gt;
  
  
  The three parts of a JWT
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;header    eyJhbGciOiJIUzI1NiJ9
payload   eyJzdWIiOiIxMjMiLCJleHAiOjE3MDAwMDAwMDB9
signature &amp;lt;binary signature, Base64URL-encoded&amp;gt;

Joined with dots:  header.payload.signature
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Decoding the first two segments (Base64URL, then JSON) gives you this:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight json"&gt;&lt;code&gt;&lt;span class="err"&gt;//&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="err"&gt;header&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nl"&gt;"alg"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"HS256"&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;

&lt;/span&gt;&lt;span class="err"&gt;//&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="err"&gt;payload&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nl"&gt;"sub"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"123"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nl"&gt;"exp"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mi"&gt;1700000000&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;ul&gt;
&lt;li&gt;Header: metadata about the token, mainly the signing algorithm (alg) and sometimes the token type (typ) or a key ID (kid).&lt;/li&gt;
&lt;li&gt;Payload: the claims. Registered claims include iss (issuer), sub (subject), aud (audience), exp (expiry), nbf (not before), and iat (issued at). Apps add their own, like roles or a user ID.&lt;/li&gt;
&lt;li&gt;Signature: a cryptographic signature over the header and payload. It proves the token wasn't altered and was issued by someone holding the key.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  How to decode one by hand
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;Split the token on the two dots to get three segments.&lt;/li&gt;
&lt;li&gt;Take the first segment, swap - for + and _ for /, add = padding until the length is a multiple of 4, and Base64-decode it.&lt;/li&gt;
&lt;li&gt;Parse the result as JSON. That is your header.&lt;/li&gt;
&lt;li&gt;Repeat for the second segment to read the payload.&lt;/li&gt;
&lt;li&gt;Leave the signature alone; it is binary data, not JSON.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;In a browser console that is one line: JSON.parse(atob(token.split('.')[1].replace(/-/g, '+').replace(/_/g, '/'))). Note that atob can mangle non-ASCII characters, which is one reason a purpose-built decoder is less error-prone.&lt;/p&gt;

&lt;h2&gt;
  
  
  Decoding is not verifying
&lt;/h2&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;The most common JWT mistake&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;A token that decodes into a perfectly sensible payload has not been checked at all. Anyone can craft a token with any claims they like; only signature verification tells you whether to trust it.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Verification happens on your server with the right key. It should also check that exp is in the future, that iss and aud match what you expect, and that the alg is one you allow. Never trust the alg header blindly: rejecting the none algorithm and pinning the expected algorithm closes a well-known class of attacks.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why you shouldn't paste live tokens into random sites
&lt;/h2&gt;

&lt;p&gt;An access token is a credential. Until it expires, whoever holds it can usually act as that user. Many online decoders send whatever you paste to their backend, or load third-party scripts that could log it. Even if the site is honest, you have copied a secret into a place you don't control.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Prefer a decoder that runs entirely in your browser.&lt;/li&gt;
&lt;li&gt;Open your browser's Network tab while you decode; nothing should be sent.&lt;/li&gt;
&lt;li&gt;Use tokens from a test environment whenever possible.&lt;/li&gt;
&lt;li&gt;If you have pasted a production token somewhere you don't trust, revoke or rotate it.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  A quick JWT debugging checklist
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Getting 401 errors? Compare exp with the current time; expired tokens are the number one cause. Remember exp is in seconds, not milliseconds.&lt;/li&gt;
&lt;li&gt;Token rejected as "not yet valid"? Check nbf and iat against clock skew between servers.&lt;/li&gt;
&lt;li&gt;Wrong audience or issuer? Read aud and iss in the payload and compare them with your server's configuration.&lt;/li&gt;
&lt;li&gt;Unexpected permissions? Look at role, scope, or permission claims; they may differ from what you assumed.&lt;/li&gt;
&lt;li&gt;Never store secrets, passwords, or personal data in the payload; it is readable by everyone who sees the token.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Frequently asked questions
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Can anyone read the contents of a JWT?
&lt;/h3&gt;

&lt;p&gt;Yes. A standard signed JWT (JWS) is only encoded, not encrypted, so anyone with the token can decode the header and payload. Only the signature protects integrity. If you need the contents hidden, use an encrypted JWT (JWE) or keep sensitive data out of the token.&lt;/p&gt;

&lt;h3&gt;
  
  
  Is it safe to decode a JWT online?
&lt;/h3&gt;

&lt;p&gt;Only if the decoder runs entirely in your browser and you can confirm nothing is uploaded. Treat any production token you paste into an untrusted site as exposed and rotate it.&lt;/p&gt;

&lt;h3&gt;
  
  
  What is the difference between decoding and verifying a JWT?
&lt;/h3&gt;

&lt;p&gt;Decoding reads the header and payload. Verifying checks the signature with the correct key and validates claims like exp, iss, and aud. Only verification proves the token is genuine.&lt;/p&gt;

&lt;h3&gt;
  
  
  Why does my JWT say it is expired?
&lt;/h3&gt;

&lt;p&gt;The exp claim is a Unix timestamp in seconds. If the current time is past that value, the token has expired. Check server clock drift if it expires too early.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Try it:&lt;/strong&gt; &lt;a href="https://base64.ilovekit.app/jwt" rel="noopener noreferrer"&gt;JWT Decoder&lt;/a&gt; — free, runs in your browser, nothing is uploaded.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://ilovekit.app/blog/how-to-decode-a-jwt-safely" rel="noopener noreferrer"&gt;ilovekit.app&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>encoding</category>
      <category>webdev</category>
      <category>programming</category>
      <category>tutorial</category>
    </item>
    <item>
      <title>What a Cron Expression Actually Means (With Examples)</title>
      <dc:creator>pulkitgovrani</dc:creator>
      <pubDate>Sat, 26 Sep 2026 07:16:46 +0000</pubDate>
      <link>https://dev.to/pulkitgovrani/what-a-cron-expression-actually-means-with-examples-4kcl</link>
      <guid>https://dev.to/pulkitgovrani/what-a-cron-expression-actually-means-with-examples-4kcl</guid>
      <description>&lt;p&gt;Cron is the classic Unix job scheduler, and its schedule syntax has spread far beyond it: CI pipelines, cloud schedulers, and job queues all accept cron expressions. The syntax is compact, which makes it easy to get subtly wrong. Here is how to read and write it with confidence.&lt;/p&gt;

&lt;h2&gt;
  
  
  The five fields
&lt;/h2&gt;

&lt;p&gt;A standard cron expression has five space-separated fields. Read left to right, they say when a job should run:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight conf"&gt;&lt;code&gt;&lt;span class="n"&gt;minute&lt;/span&gt;   &lt;span class="n"&gt;hour&lt;/span&gt;   &lt;span class="n"&gt;day&lt;/span&gt;-&lt;span class="n"&gt;of&lt;/span&gt;-&lt;span class="n"&gt;month&lt;/span&gt;   &lt;span class="n"&gt;month&lt;/span&gt;   &lt;span class="n"&gt;day&lt;/span&gt;-&lt;span class="n"&gt;of&lt;/span&gt;-&lt;span class="n"&gt;week&lt;/span&gt;
&lt;span class="m"&gt;0&lt;/span&gt;-&lt;span class="m"&gt;59&lt;/span&gt;     &lt;span class="m"&gt;0&lt;/span&gt;-&lt;span class="m"&gt;23&lt;/span&gt;   &lt;span class="m"&gt;1&lt;/span&gt;-&lt;span class="m"&gt;31&lt;/span&gt;           &lt;span class="m"&gt;1&lt;/span&gt;-&lt;span class="m"&gt;12&lt;/span&gt;    &lt;span class="m"&gt;0&lt;/span&gt;-&lt;span class="m"&gt;6&lt;/span&gt; (&lt;span class="n"&gt;Sunday&lt;/span&gt; = &lt;span class="m"&gt;0&lt;/span&gt;)
*        *      *              *       *
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;A job runs when the current time matches every field. A * means "every possible value" for that field.&lt;/p&gt;

&lt;h2&gt;
  
  
  The special characters
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;* matches every value in the field.&lt;/li&gt;
&lt;li&gt;, separates a list: 1,15 means the 1st and the 15th.&lt;/li&gt;
&lt;li&gt;- defines a range: 1-5 means 1 through 5 (Monday to Friday in the day-of-week field).&lt;/li&gt;
&lt;li&gt;/ defines a step: */15 means every 15 units, and 10-40/10 means 10, 20, 30, 40.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Common schedules
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;*/5 * * * * runs every 5 minutes.&lt;/li&gt;
&lt;li&gt;0 * * * * runs at the top of every hour.&lt;/li&gt;
&lt;li&gt;0 9 * * 1-5 runs at 09:00 on weekdays.&lt;/li&gt;
&lt;li&gt;30 2 * * 0 runs at 02:30 every Sunday.&lt;/li&gt;
&lt;li&gt;0 0 1 * * runs at midnight on the first of every month.&lt;/li&gt;
&lt;li&gt;0 0 1 1 * runs once a year, at midnight on 1 January.&lt;/li&gt;
&lt;li&gt;15 14 1 * * runs at 14:15 on the 1st of each month.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  The gotchas that cause missed jobs
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Time zones
&lt;/h3&gt;

&lt;p&gt;Cron runs in the time zone of the machine or service, which is very often UTC. A job you wrote as "9 AM" may fire at 9 AM UTC, not in your local time. Cloud schedulers usually let you set a time zone explicitly; check before you assume.&lt;/p&gt;

&lt;h3&gt;
  
  
  Day of month plus day of week
&lt;/h3&gt;

&lt;p&gt;In classic Vixie cron, if you restrict both the day-of-month and the day-of-week fields, the job runs when either one matches, not both. 0 0 13 * 5 fires on every 13th and on every Friday, not only on Friday the 13th. Other schedulers may behave differently, so read their docs.&lt;/p&gt;

&lt;h3&gt;
  
  
  Dialect differences
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Some systems (Quartz, Spring, AWS EventBridge) add a seconds or year field, so expressions have six or seven fields.&lt;/li&gt;
&lt;li&gt;Some support names such as MON or JAN and shortcuts like @daily or @hourly; others do not.&lt;/li&gt;
&lt;li&gt;Characters like L, W, and # (last day, nearest weekday, nth weekday) exist in some dialects only.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Daylight saving time
&lt;/h3&gt;

&lt;p&gt;In a local time zone that observes daylight saving, a job scheduled during the skipped hour may not run, and one in the repeated hour may run twice. Scheduling in UTC avoids the problem entirely.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Sanity-check before you deploy&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Paste the expression into a parser and read the plain-English translation. If it doesn't say what you meant, fix it before it silently runs at the wrong time in production.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  Frequently asked questions
&lt;/h2&gt;

&lt;h3&gt;
  
  
  What does */5 * * * * mean in cron?
&lt;/h3&gt;

&lt;p&gt;It means run every 5 minutes: the */5 in the minute field is a step of 5, and the other fields are wildcards.&lt;/p&gt;

&lt;h3&gt;
  
  
  How do I run a cron job every day at midnight?
&lt;/h3&gt;

&lt;p&gt;Use 0 0 * * *. That is minute 0, hour 0, every day of the month, every month, every day of the week.&lt;/p&gt;

&lt;h3&gt;
  
  
  Does cron use UTC or local time?
&lt;/h3&gt;

&lt;p&gt;It uses the time zone of the machine or scheduling service running it. Many servers and cloud schedulers default to UTC, so confirm and set the time zone explicitly when it matters.&lt;/p&gt;

&lt;h3&gt;
  
  
  What is the difference between 5-field and 6-field cron?
&lt;/h3&gt;

&lt;p&gt;Standard Unix cron has five fields (minute to day of week). Some schedulers add a leading seconds field, or a trailing year field, so always check which format your tool expects.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Try it:&lt;/strong&gt; &lt;a href="https://dev.ilovekit.app/cron" rel="noopener noreferrer"&gt;Cron Expression Parser&lt;/a&gt; — free, runs in your browser, nothing is uploaded.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://ilovekit.app/blog/what-a-cron-expression-means" rel="noopener noreferrer"&gt;ilovekit.app&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>developer</category>
      <category>webdev</category>
      <category>programming</category>
      <category>tutorial</category>
    </item>
    <item>
      <title>Why You Should Remove EXIF Data Before Sharing Photos</title>
      <dc:creator>pulkitgovrani</dc:creator>
      <pubDate>Sat, 26 Sep 2026 07:16:34 +0000</pubDate>
      <link>https://dev.to/pulkitgovrani/why-you-should-remove-exif-data-before-sharing-photos-1a1e</link>
      <guid>https://dev.to/pulkitgovrani/why-you-should-remove-exif-data-before-sharing-photos-1a1e</guid>
      <description>&lt;p&gt;Every photo from a phone or camera carries a block of hidden information called EXIF (Exchangeable Image File Format) metadata. It is useful for photographers and for organizing libraries, but it can reveal far more than you intend when you share an image publicly or send it to a stranger.&lt;/p&gt;

&lt;h2&gt;
  
  
  What EXIF data can contain
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Device details: camera or phone make and model, lens, and sometimes the serial number.&lt;/li&gt;
&lt;li&gt;Capture settings: exposure, aperture, ISO, focal length, and flash.&lt;/li&gt;
&lt;li&gt;Date and time: when the photo was taken, often to the second.&lt;/li&gt;
&lt;li&gt;Location: GPS latitude and longitude, altitude, and sometimes direction, if location tagging was on.&lt;/li&gt;
&lt;li&gt;Software: the app that edited or exported the file.&lt;/li&gt;
&lt;li&gt;Orientation and a small embedded thumbnail, which can occasionally still show the original image after cropping.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Why it matters
&lt;/h2&gt;

&lt;p&gt;A photo taken at home and posted publicly can carry the coordinates of that home. A picture of an item for sale can show where you live, and a series of timestamps can reveal your routine. Journalists, activists, and anyone with a stalker have very real reasons to be careful, but so does everyone else.&lt;/p&gt;

&lt;h2&gt;
  
  
  Do social networks remove it?
&lt;/h2&gt;

&lt;p&gt;Many large platforms strip location metadata from images when they're uploaded, but not all do, and policies change. Email attachments, direct file transfers, forums, classified-ad sites, cloud share links, and personal websites often keep the original file untouched. Don't assume; check, or remove it yourself before sharing.&lt;/p&gt;

&lt;h2&gt;
  
  
  How to check and remove EXIF data
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;Open the photo in a metadata viewer to see exactly what it contains, including any GPS fields.&lt;/li&gt;
&lt;li&gt;Remove the metadata and export a clean copy. The pixels stay the same; only the hidden fields are dropped.&lt;/li&gt;
&lt;li&gt;Open the cleaned file in the viewer again to confirm the location and device fields are gone.&lt;/li&gt;
&lt;li&gt;Share the cleaned copy and keep the original for your own library.&lt;/li&gt;
&lt;/ol&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Do it locally&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Uploading a personal photo to a website just to strip its metadata defeats the purpose. Use a tool that works entirely in your browser, so the image never leaves your device.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  Other ways to avoid leaking location
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Turn off location tagging for the camera app in your phone's settings.&lt;/li&gt;
&lt;li&gt;Take a screenshot of the photo. It usually has no GPS data, though it may lose quality.&lt;/li&gt;
&lt;li&gt;On iOS and Android, the share sheet often has an option to exclude location when sending a photo.&lt;/li&gt;
&lt;li&gt;Remember that the image itself can leak information: street signs, house numbers, reflections, and landmarks.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Frequently asked questions
&lt;/h2&gt;

&lt;h3&gt;
  
  
  What is EXIF data in a photo?
&lt;/h3&gt;

&lt;p&gt;EXIF is metadata embedded in image files by cameras and phones. It records details like device model, capture settings, date and time, and often GPS location.&lt;/p&gt;

&lt;h3&gt;
  
  
  Does removing EXIF data reduce image quality?
&lt;/h3&gt;

&lt;p&gt;No. Stripping metadata leaves the pixel data unchanged; only the hidden fields are removed.&lt;/p&gt;

&lt;h3&gt;
  
  
  Do screenshots contain EXIF data?
&lt;/h3&gt;

&lt;p&gt;Screenshots generally don't include GPS location, though they may include basic details like the device or software. Check with a metadata viewer if it matters.&lt;/p&gt;

&lt;h3&gt;
  
  
  Can I remove EXIF data without uploading my photo?
&lt;/h3&gt;

&lt;p&gt;Yes. A browser-based tool processes the file locally on your device, so the image is never sent to a server.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Try it:&lt;/strong&gt; &lt;a href="https://image.ilovekit.app/exif" rel="noopener noreferrer"&gt;EXIF Viewer &amp;amp; Remover&lt;/a&gt; — free, runs in your browser, nothing is uploaded.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://ilovekit.app/blog/remove-exif-data-before-sharing-photos" rel="noopener noreferrer"&gt;ilovekit.app&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>image</category>
      <category>webdev</category>
      <category>programming</category>
      <category>tutorial</category>
    </item>
    <item>
      <title>JSON vs YAML: When to Use Which</title>
      <dc:creator>pulkitgovrani</dc:creator>
      <pubDate>Sat, 26 Sep 2026 07:16:24 +0000</pubDate>
      <link>https://dev.to/pulkitgovrani/json-vs-yaml-when-to-use-which-3n6b</link>
      <guid>https://dev.to/pulkitgovrani/json-vs-yaml-when-to-use-which-3n6b</guid>
      <description>&lt;p&gt;JSON and YAML can describe the same data, so the choice comes down to who (or what) reads and writes the file. JSON is strict, small, and easy for software to parse. YAML is looser and friendlier for humans to edit. Picking the right one prevents a surprising number of config bugs.&lt;/p&gt;

&lt;h2&gt;
  
  
  The same data, two ways
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight json"&gt;&lt;code&gt;&lt;span class="err"&gt;//&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="err"&gt;JSON&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"name"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"api"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"ports"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;80&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mi"&gt;443&lt;/span&gt;&lt;span class="p"&gt;],&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"debug"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="kc"&gt;false&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"env"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nl"&gt;"NODE_ENV"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"production"&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;

&lt;/span&gt;&lt;span class="err"&gt;#&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="err"&gt;YAML&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="err"&gt;name:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="err"&gt;api&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="err"&gt;ports:&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="err"&gt;-&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mi"&gt;80&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="err"&gt;-&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mi"&gt;443&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="err"&gt;debug:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="kc"&gt;false&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="err"&gt;env:&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="err"&gt;NODE_ENV:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="err"&gt;production&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h2&gt;
  
  
  Where JSON is the better choice
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;APIs and data exchange. Every language has a fast, built-in JSON parser and the grammar is tiny.&lt;/li&gt;
&lt;li&gt;Strictness. There is one way to write each value, so there is little room for ambiguity.&lt;/li&gt;
&lt;li&gt;Machine-generated files, such as lock files and API responses, that people rarely edit by hand.&lt;/li&gt;
&lt;li&gt;Anywhere parser differences would be risky.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Where YAML is the better choice
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Configuration that humans maintain: Kubernetes manifests, GitHub Actions, Docker Compose, Ansible.&lt;/li&gt;
&lt;li&gt;Comments. YAML supports # comments, which are invaluable in config; standard JSON has none.&lt;/li&gt;
&lt;li&gt;Readability of deeply nested data, since there are no braces, brackets, or trailing-comma errors.&lt;/li&gt;
&lt;li&gt;Multi-line strings, which YAML handles cleanly with | and &amp;gt; block scalars.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  YAML pitfalls to know about
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Indentation is syntax
&lt;/h3&gt;

&lt;p&gt;Structure comes from indentation, and tabs are not allowed for indentation. One misaligned line silently changes the meaning of the document, or breaks it.&lt;/p&gt;

&lt;h3&gt;
  
  
  Unquoted values get guessed
&lt;/h3&gt;

&lt;p&gt;In YAML 1.1 (still used by many parsers) unquoted yes, no, on, and off can be read as booleans. This is the famous "Norway problem": the country code NO becomes false. Version numbers like 1.10 can become the number 1.1. Quote any value that must stay a string.&lt;/p&gt;

&lt;h3&gt;
  
  
  A big spec, so parsers vary
&lt;/h3&gt;

&lt;p&gt;YAML has anchors, aliases, tags, and multiple document forms. Different parsers support different subsets, so the same file can behave differently across tools. Loading untrusted YAML with a full-featured loader can also be a security risk; use a safe loader.&lt;/p&gt;

&lt;h2&gt;
  
  
  A simple rule of thumb
&lt;/h2&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Use JSON when software talks to software&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Use YAML when humans maintain the file. If a config file needs comments or is edited often by people, prefer YAML; if it's an API payload or generated data, prefer JSON.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  Converting between them safely
&lt;/h2&gt;

&lt;p&gt;Converting JSON to YAML is lossless, but going the other way can drop comments and anchors. Re-validate the result after any conversion. Config files often contain hostnames and secrets, so convert them with a tool that runs locally in your browser.&lt;/p&gt;

&lt;h2&gt;
  
  
  Frequently asked questions
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Is YAML a superset of JSON?
&lt;/h3&gt;

&lt;p&gt;Since YAML 1.2, valid JSON is intended to be valid YAML, so most JSON documents parse as YAML. The reverse is not true.&lt;/p&gt;

&lt;h3&gt;
  
  
  Why doesn't JSON support comments?
&lt;/h3&gt;

&lt;p&gt;The format was kept deliberately minimal. If you need comments, use JSONC, JSON5, or YAML, or keep documentation outside the file.&lt;/p&gt;

&lt;h3&gt;
  
  
  Which is faster to parse, JSON or YAML?
&lt;/h3&gt;

&lt;p&gt;JSON is generally much faster and simpler to parse, which is one reason it dominates APIs.&lt;/p&gt;

&lt;h3&gt;
  
  
  Should I use YAML for API responses?
&lt;/h3&gt;

&lt;p&gt;Almost never. JSON is the standard for APIs because of its strictness, speed, and universal support.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Try it:&lt;/strong&gt; &lt;a href="https://json.ilovekit.app/yaml" rel="noopener noreferrer"&gt;JSON to YAML Converter&lt;/a&gt; — free, runs in your browser, nothing is uploaded.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://ilovekit.app/blog/json-vs-yaml-when-to-use-which" rel="noopener noreferrer"&gt;ilovekit.app&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>json</category>
      <category>webdev</category>
      <category>programming</category>
      <category>tutorial</category>
    </item>
    <item>
      <title>How to Fix "Unexpected Token" and Other Invalid JSON Errors</title>
      <dc:creator>pulkitgovrani</dc:creator>
      <pubDate>Sat, 26 Sep 2026 07:16:10 +0000</pubDate>
      <link>https://dev.to/pulkitgovrani/how-to-fix-unexpected-token-and-other-invalid-json-errors-1ndf</link>
      <guid>https://dev.to/pulkitgovrani/how-to-fix-unexpected-token-and-other-invalid-json-errors-1ndf</guid>
      <description>&lt;p&gt;Errors such as "Unexpected token } in JSON at position 42" or "Expected property name or '}'" almost always come from a small syntax slip. JSON is stricter than JavaScript object syntax, and it is easy to write something that looks fine but is not valid. These are the mistakes behind the vast majority of parse errors.&lt;/p&gt;

&lt;h2&gt;
  
  
  1. Trailing commas
&lt;/h2&gt;

&lt;p&gt;JSON does not allow a comma after the last item in an object or array. This is the single most common error, especially after deleting a line from the end of a list.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight json"&gt;&lt;code&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nl"&gt;"a"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nl"&gt;"b"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mi"&gt;2&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;    &lt;/span&gt;&lt;span class="err"&gt;//&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="err"&gt;invalid&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nl"&gt;"a"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nl"&gt;"b"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mi"&gt;2&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;     &lt;/span&gt;&lt;span class="err"&gt;//&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="err"&gt;valid&lt;/span&gt;&lt;span class="w"&gt;

&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mi"&gt;2&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mi"&gt;3&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="w"&gt;              &lt;/span&gt;&lt;span class="err"&gt;//&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="err"&gt;invalid&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mi"&gt;2&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mi"&gt;3&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="w"&gt;                &lt;/span&gt;&lt;span class="err"&gt;//&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="err"&gt;valid&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h2&gt;
  
  
  2. Single quotes
&lt;/h2&gt;

&lt;p&gt;Strings and keys must use double quotes. { 'name': 'Ada' } is valid JavaScript but invalid JSON. Replace every single quote used as a delimiter with a double quote, and escape any double quote inside a string as \".&lt;/p&gt;

&lt;h2&gt;
  
  
  3. Unquoted keys
&lt;/h2&gt;

&lt;p&gt;In JavaScript you can write { name: "Ada" }. In JSON every key must be a double-quoted string: { "name": "Ada" }.&lt;/p&gt;

&lt;h2&gt;
  
  
  4. Comments
&lt;/h2&gt;

&lt;p&gt;Standard JSON has no comments. Neither // nor /* */ is allowed. If you need comments, use a superset such as JSONC (used by editors like VS Code) or a format like YAML, or strip the comments before parsing.&lt;/p&gt;

&lt;h2&gt;
  
  
  5. Values JSON does not support
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;undefined, NaN, and Infinity are not valid JSON values. Use null or a string instead.&lt;/li&gt;
&lt;li&gt;Numbers cannot have leading zeros (007) or a leading plus sign, and hex like 0xFF is not allowed.&lt;/li&gt;
&lt;li&gt;Strings cannot contain raw newlines or tabs; escape them as \n and \t.&lt;/li&gt;
&lt;li&gt;Dates have no native type; store them as ISO 8601 strings.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  6. Invisible and structural problems
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;A byte-order mark (BOM) at the start of a file can trigger "unexpected token" at position 0.&lt;/li&gt;
&lt;li&gt;Two objects back to back ({...}{...}) instead of a single object or an array.&lt;/li&gt;
&lt;li&gt;A truncated response: the payload was cut off, so a closing brace or bracket is missing.&lt;/li&gt;
&lt;li&gt;The response is actually HTML (an error page or a login redirect) rather than JSON, which shows up as "Unexpected token &amp;lt;".&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  How to find the problem fast
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;Copy the exact text that is being parsed, not what you think it contains.&lt;/li&gt;
&lt;li&gt;Paste it into a validator; it should point to the line and column of the first error.&lt;/li&gt;
&lt;li&gt;Look at the character just before the reported position. The real mistake is usually right there, such as a missing comma or an extra one.&lt;/li&gt;
&lt;li&gt;Fix one error at a time and re-validate; later errors are often hidden behind the first.&lt;/li&gt;
&lt;li&gt;If the error is at position 0 and you see "&amp;lt;", log the raw response body and check the HTTP status.&lt;/li&gt;
&lt;/ol&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Keep real data private&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;API responses often contain tokens, emails, and other personal data. Validate them with a tool that runs in your browser, so the payload isn't uploaded to someone else's server.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  Frequently asked questions
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Why does JSON.parse say "Unexpected token &amp;lt; in JSON at position 0"?
&lt;/h3&gt;

&lt;p&gt;The text starts with a "&amp;lt;", which almost always means you received an HTML page (a 404, 500, or login page) instead of JSON. Check the HTTP status and log the raw response.&lt;/p&gt;

&lt;h3&gt;
  
  
  Can JSON have comments or trailing commas?
&lt;/h3&gt;

&lt;p&gt;Not in standard JSON. Comments and trailing commas are allowed in supersets such as JSONC or JSON5, but a strict parser will reject them.&lt;/p&gt;

&lt;h3&gt;
  
  
  Are single quotes valid in JSON?
&lt;/h3&gt;

&lt;p&gt;No. Keys and string values must use double quotes.&lt;/p&gt;

&lt;h3&gt;
  
  
  How do I validate JSON without uploading it?
&lt;/h3&gt;

&lt;p&gt;Use a validator that runs client-side in your browser and confirm in the Network tab that no request is made when you paste your data.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Try it:&lt;/strong&gt; &lt;a href="https://json.ilovekit.app" rel="noopener noreferrer"&gt;JSON Formatter &amp;amp; Validator&lt;/a&gt; — free, runs in your browser, nothing is uploaded.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://ilovekit.app/blog/how-to-fix-invalid-json-errors" rel="noopener noreferrer"&gt;ilovekit.app&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>json</category>
      <category>webdev</category>
      <category>programming</category>
      <category>tutorial</category>
    </item>
    <item>
      <title>Regex Cheatsheet for Beginners (With Copy-Paste Examples)</title>
      <dc:creator>pulkitgovrani</dc:creator>
      <pubDate>Sat, 26 Sep 2026 07:15:55 +0000</pubDate>
      <link>https://dev.to/pulkitgovrani/regex-cheatsheet-for-beginners-with-copy-paste-examples-4joe</link>
      <guid>https://dev.to/pulkitgovrani/regex-cheatsheet-for-beginners-with-copy-paste-examples-4joe</guid>
      <description>&lt;p&gt;Regular expressions look cryptic at first, but a small set of building blocks covers most real-world tasks: validating input, searching logs, and doing bulk find-and-replace. Learn these pieces and you can read and write most patterns you'll meet.&lt;/p&gt;

&lt;h2&gt;
  
  
  The basic building blocks
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;. matches any single character except a newline.&lt;/li&gt;
&lt;li&gt;\d matches a digit, \w a word character (letters, digits, underscore), and \s whitespace. The capitals \D, \W, and \S mean the opposite.&lt;/li&gt;
&lt;li&gt;[abc] matches any one of a, b, or c. [a-z] is a range, and [^abc] matches anything except those.&lt;/li&gt;
&lt;li&gt;^ and $ match the start and end of the string (or of each line with the m flag).&lt;/li&gt;
&lt;li&gt;\b matches a word boundary, which is handy for whole-word matches.&lt;/li&gt;
&lt;li&gt;Use a backslash to match a special character literally: \. matches a period, \( a parenthesis.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Quantifiers: how many times
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;* means zero or more, + means one or more, and ? means zero or one.&lt;/li&gt;
&lt;li&gt;{3} means exactly 3, {2,5} means between 2 and 5, and {2,} means 2 or more.&lt;/li&gt;
&lt;li&gt;Quantifiers are greedy by default and grab as much as they can. Add a ? after one (like .*?) to make it lazy so it matches as little as possible.
&lt;/li&gt;
&lt;/ul&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;&amp;lt;.+&amp;gt;     // greedy: on "&amp;lt;b&amp;gt;hi&amp;lt;/b&amp;gt;" matches the whole string
&amp;lt;.+?&amp;gt;    // lazy:   matches "&amp;lt;b&amp;gt;" first
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h2&gt;
  
  
  Groups, alternation, and backreferences
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;(cat|dog)s?                      // cat, cats, dog, dogs
(\d{4})-(\d{2})-(\d{2})         // capture year, month, day
(?&amp;lt;year&amp;gt;\d{4})-(?&amp;lt;month&amp;gt;\d{2})   // named groups
(?:abc)+                         // group without capturing
(\w)\1                           // a repeated character, like "ll" in "hello"
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h2&gt;
  
  
  Lookaheads and lookbehinds
&lt;/h2&gt;

&lt;p&gt;Lookarounds check what surrounds a position without including it in the match.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;\d+(?= dollars)      // digits followed by " dollars"
\d+(?! dollars)      // digits NOT followed by " dollars"
(?&amp;lt;=\$)\d+           // digits preceded by "$"
(?&amp;lt;!\$)\b\d+          // digits NOT preceded by "$"
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h2&gt;
  
  
  Flags
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;g finds all matches instead of stopping at the first.&lt;/li&gt;
&lt;li&gt;i makes the match case-insensitive.&lt;/li&gt;
&lt;li&gt;m makes ^ and $ match at line boundaries.&lt;/li&gt;
&lt;li&gt;s lets . match newlines as well.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Practical patterns you can reuse
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;ISO date (format only): ^\d{4}-\d{2}-\d{2}$&lt;/li&gt;
&lt;li&gt;Hex color: ^#(?:[0-9a-fA-F]{3}){1,2}$&lt;/li&gt;
&lt;li&gt;Simple email shape: ^[^\s@]+@[^\s@]+\.[^\s@]+$&lt;/li&gt;
&lt;li&gt;Trim extra spaces: \s{2,} replaced with a single space&lt;/li&gt;
&lt;li&gt;Slug: ^[a-z0-9]+(?:-[a-z0-9]+)*$&lt;/li&gt;
&lt;/ul&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Regex checks shape, not truth&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The email pattern above accepts anything that looks like an address. Confirming an address actually exists means sending a message to it. Likewise, the date pattern accepts 2026-13-45; validate the values in code.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  Common mistakes
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Forgetting to escape special characters like . and ?, which then match far more than intended.&lt;/li&gt;
&lt;li&gt;Using greedy .* and swallowing more text than you meant to.&lt;/li&gt;
&lt;li&gt;Nested quantifiers such as (a+)+ that can cause catastrophic backtracking on certain inputs and freeze your program.&lt;/li&gt;
&lt;li&gt;Assuming every engine behaves the same; lookbehind and named-group syntax differ between JavaScript, Python, and PCRE.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The fastest way to learn is to test against sample text and watch each match and group light up. Build the pattern one piece at a time.&lt;/p&gt;

&lt;h2&gt;
  
  
  Frequently asked questions
&lt;/h2&gt;

&lt;h3&gt;
  
  
  What does \d+ mean in regex?
&lt;/h3&gt;

&lt;p&gt;\d matches a single digit and + means one or more, so \d+ matches a run of one or more digits, like 2026.&lt;/p&gt;

&lt;h3&gt;
  
  
  What is the difference between greedy and lazy quantifiers?
&lt;/h3&gt;

&lt;p&gt;A greedy quantifier (.*) matches as much as possible; a lazy one (.*?) matches as little as possible. Lazy is often what you want when matching between delimiters.&lt;/p&gt;

&lt;h3&gt;
  
  
  How do I match a literal dot or bracket?
&lt;/h3&gt;

&lt;p&gt;Escape it with a backslash: \. matches a period and \[ matches an opening bracket.&lt;/p&gt;

&lt;h3&gt;
  
  
  Is regex the right tool to validate an email address?
&lt;/h3&gt;

&lt;p&gt;A simple shape check is fine for a form, but regex cannot prove an address exists. Send a confirmation email for real verification.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Try it:&lt;/strong&gt; &lt;a href="https://regex.ilovekit.app" rel="noopener noreferrer"&gt;Regex Tester&lt;/a&gt; — free, runs in your browser, nothing is uploaded.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://ilovekit.app/blog/regex-cheatsheet-for-beginners" rel="noopener noreferrer"&gt;ilovekit.app&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>regex</category>
      <category>webdev</category>
      <category>programming</category>
      <category>tutorial</category>
    </item>
    <item>
      <title>Base64 Is Not Encryption (And Other Common Misconceptions)</title>
      <dc:creator>pulkitgovrani</dc:creator>
      <pubDate>Sat, 26 Sep 2026 07:15:40 +0000</pubDate>
      <link>https://dev.to/pulkitgovrani/base64-is-not-encryption-and-other-common-misconceptions-23be</link>
      <guid>https://dev.to/pulkitgovrani/base64-is-not-encryption-and-other-common-misconceptions-23be</guid>
      <description>&lt;p&gt;Base64 shows up everywhere: emails, data URLs, HTTP headers, JWTs. Because the output looks scrambled, it is often mistaken for encryption. It isn't. Base64 is an encoding: a reversible way to represent binary data as plain text, with no key and no secret.&lt;/p&gt;

&lt;h2&gt;
  
  
  How Base64 works
&lt;/h2&gt;

&lt;p&gt;Base64 takes your data three bytes (24 bits) at a time and splits them into four groups of six bits. Each 6-bit value (0 to 63) maps to one character from an alphabet of 64: A-Z, a-z, 0-9, +, and /. If the input length isn't a multiple of three, the output is padded with = characters.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;"hello"   →  aGVsbG8=
"hello!"  →  aGVsbG8h
"hi"      →  aGk=
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Going the other way needs nothing but the same table, so anyone can decode it in seconds.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Never rely on Base64 to hide anything&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;If a password, API key, or token is only Base64-encoded, treat it as plain text. Anyone who sees it can read it.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  What Base64 is genuinely for
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Moving binary data through text-only channels, such as email attachments (MIME) and JSON fields.&lt;/li&gt;
&lt;li&gt;Embedding small images or fonts directly in HTML or CSS as data: URLs.&lt;/li&gt;
&lt;li&gt;The HTTP Basic authentication header, which Base64-encodes username:password. This offers no protection, so it must only be used over HTTPS.&lt;/li&gt;
&lt;li&gt;JWTs, which use the URL-safe variant for their three segments.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Details worth knowing
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Size overhead: the output is about 33% larger than the input, because 3 bytes become 4 characters.&lt;/li&gt;
&lt;li&gt;URL-safe Base64 replaces + and / with - and _ and often drops the = padding, so the result can sit safely in URLs and filenames.&lt;/li&gt;
&lt;li&gt;Text encoding matters: convert text to bytes (usually UTF-8) before encoding, or non-ASCII characters will break. Browser atob and btoa only handle Latin-1 directly.&lt;/li&gt;
&lt;li&gt;Base64 is not compression; it always makes data bigger.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Encoding vs hashing vs encryption
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Encoding (Base64, URL encoding) changes the representation. It is reversible by anyone and provides no secrecy.&lt;/li&gt;
&lt;li&gt;Hashing (SHA-256, bcrypt) is one-way. You can't get the original back, only check whether an input matches.&lt;/li&gt;
&lt;li&gt;Encryption (AES-GCM, ChaCha20) is reversible only with the right key. This is what provides confidentiality.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  If you need secrecy
&lt;/h2&gt;

&lt;p&gt;Use authenticated encryption such as AES-GCM with a properly generated key, or a well-reviewed library that does it for you. Store passwords with a slow, salted hash such as bcrypt or Argon2. Never invent your own scheme, and never treat Base64 as a security layer.&lt;/p&gt;

&lt;h2&gt;
  
  
  Frequently asked questions
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Is Base64 encryption?
&lt;/h3&gt;

&lt;p&gt;No. Base64 is a reversible encoding with no key, so anyone can decode it. It provides no confidentiality.&lt;/p&gt;

&lt;h3&gt;
  
  
  Why does Base64 make data larger?
&lt;/h3&gt;

&lt;p&gt;Every 3 bytes of input become 4 characters of output, so the encoded data is roughly 33% bigger.&lt;/p&gt;

&lt;h3&gt;
  
  
  What does the = at the end of Base64 mean?
&lt;/h3&gt;

&lt;p&gt;It is padding, added when the input length isn't a multiple of three bytes. URL-safe variants often omit it.&lt;/p&gt;

&lt;h3&gt;
  
  
  What is URL-safe Base64?
&lt;/h3&gt;

&lt;p&gt;A variant that replaces + and / with - and _ so the output can be used safely in URLs, filenames, and JWTs.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Try it:&lt;/strong&gt; &lt;a href="https://base64.ilovekit.app" rel="noopener noreferrer"&gt;Base64 &amp;amp; URL Encoder&lt;/a&gt; — free, runs in your browser, nothing is uploaded.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://ilovekit.app/blog/base64-is-not-encryption" rel="noopener noreferrer"&gt;ilovekit.app&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>encoding</category>
      <category>webdev</category>
      <category>programming</category>
      <category>tutorial</category>
    </item>
    <item>
      <title>How Strong Should a Password Be? Length vs. Complexity</title>
      <dc:creator>pulkitgovrani</dc:creator>
      <pubDate>Sat, 26 Sep 2026 07:15:27 +0000</pubDate>
      <link>https://dev.to/pulkitgovrani/how-strong-should-a-password-be-length-vs-complexity-dg1</link>
      <guid>https://dev.to/pulkitgovrani/how-strong-should-a-password-be-length-vs-complexity-dg1</guid>
      <description>&lt;p&gt;Password strength is really a question of how many guesses an attacker would need. Every extra character multiplies that number, which is why length matters far more than swapping an a for an @. Understanding this lets you stop memorizing rules and start choosing passwords that hold up.&lt;/p&gt;

&lt;h2&gt;
  
  
  Entropy: the number behind strength
&lt;/h2&gt;

&lt;p&gt;Entropy measures unpredictability in bits; each extra bit doubles the number of guesses needed. For a password picked uniformly at random from a set of characters, entropy is length multiplied by log2 of the set size. A random character from the roughly 94 printable ASCII characters adds about 6.5 bits.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;8 random characters is about 52 bits.&lt;/li&gt;
&lt;li&gt;12 random characters is about 79 bits.&lt;/li&gt;
&lt;li&gt;16 random characters is about 105 bits.&lt;/li&gt;
&lt;li&gt;20 random characters is about 131 bits.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;These figures only apply to genuinely random passwords. Human-chosen ones are far weaker than their length suggests.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why clever tricks don't help much
&lt;/h2&gt;

&lt;p&gt;Attackers don't try every combination in order. They start with leaked-password lists, common words, keyboard patterns, names, dates, and predictable substitutions (P@ssw0rd!). A password like Summer2026! looks complex, but it follows a pattern crackers try early, so its real strength is low.&lt;/p&gt;

&lt;h2&gt;
  
  
  Passphrases: long and memorable
&lt;/h2&gt;

&lt;p&gt;A passphrase made of several random, unrelated words is easier to remember and can be very strong. The catch is that the words must be chosen randomly (for example with dice or a generator), not picked because they feel meaningful. Each word from a 7,776-word list adds about 12.9 bits, so five words is roughly 65 bits and six is roughly 78 bits.&lt;/p&gt;

&lt;h2&gt;
  
  
  A simple set of rules that works
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;Use a password manager and let it generate a unique random password of 16+ characters for every account.&lt;/li&gt;
&lt;li&gt;For the few passwords you must remember (the manager itself, your device), use a random passphrase of five or six words.&lt;/li&gt;
&lt;li&gt;Never reuse passwords. Reuse is how one breach turns into ten.&lt;/li&gt;
&lt;li&gt;Turn on two-factor authentication wherever it's offered, preferably with an authenticator app or a hardware key.&lt;/li&gt;
&lt;li&gt;Change a password when you have a reason to (a breach, sharing, suspicion), not on a fixed schedule.&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  What about length limits and special characters?
&lt;/h2&gt;

&lt;p&gt;Modern guidance (such as NIST's) favors length over composition rules and discourages forced periodic changes. Sites that cap passwords at short lengths or forbid certain characters are working against you; a password manager helps you work around them.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Check strength privately&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Don't paste real passwords into a checker that sends them to a server. Use one that runs entirely in your browser, and assume any password you've pasted into an untrusted site is compromised.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  Frequently asked questions
&lt;/h2&gt;

&lt;h3&gt;
  
  
  How long should a password be in 2026?
&lt;/h3&gt;

&lt;p&gt;For accounts protected by a manager, 16 or more random characters. For a memorized passphrase, five or six random words.&lt;/p&gt;

&lt;h3&gt;
  
  
  Are passphrases more secure than passwords?
&lt;/h3&gt;

&lt;p&gt;A random passphrase of enough words can be as strong as a random character password while being much easier to remember and type.&lt;/p&gt;

&lt;h3&gt;
  
  
  Do special characters make a password stronger?
&lt;/h3&gt;

&lt;p&gt;A bit, but length adds much more. A longer password beats a short one with symbols, especially if the symbols follow predictable patterns.&lt;/p&gt;

&lt;h3&gt;
  
  
  Should I change my passwords regularly?
&lt;/h3&gt;

&lt;p&gt;Not on a fixed schedule. Change them after a breach or suspicious activity, and use unique passwords with two-factor authentication instead.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Try it:&lt;/strong&gt; &lt;a href="https://password.ilovekit.app/strength" rel="noopener noreferrer"&gt;Password Strength Checker&lt;/a&gt; — free, runs in your browser, nothing is uploaded.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://ilovekit.app/blog/how-strong-should-a-password-be" rel="noopener noreferrer"&gt;ilovekit.app&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>security</category>
      <category>webdev</category>
      <category>programming</category>
      <category>tutorial</category>
    </item>
  </channel>
</rss>
