Disclosure: I'm part of the team behind IO Tools (iotools.cloud), the site every link below points to. They're all free and need no account. I've stuck to tools whose pages say processing happens in your browser.
We've all done it: an API response, a JWT or a config file needs a quick look, so you paste it into the first "online formatter" you find. That token might be a live production credential, and that config might hold a connection string.
The fix is simple: use tools that do the work client-side, so the data never leaves your machine. Here are 12 I reach for every week, in roughly the order they come up while debugging.
1. JSON Formatter: make a minified blob readable
https://iotools.cloud/tool/json-formatter/
Paste a one-line API response and get it indented, validated and (optionally) with sorted keys, which is handy for diffing two responses. The page says parsing and formatting run entirely in your browser, so it's safe for responses you wouldn't paste into a random server.
Tip: sort the keys before you diff. Half the "differences" between two JSON payloads are just key order.
2. JSON Compare: what actually changed?
https://iotools.cloud/tool/json-compare/
Diffing JSON as text is noisy. This tool compares by structure (objects by key, arrays by index) and lists every added, removed and changed value by its key path. Great for "it worked yesterday" moments.
3. JSONPath Tester: pull one value out of a huge payload
https://iotools.cloud/tool/jsonpath-tester/
When a response is 4,000 lines and you need $.data.items[*].id, test the expression here first. It supports wildcards, recursive descent, slices and filter expressions, so you can check your path before it goes into code or a jq script.
4. JSON to TypeScript: types from a real response
https://iotools.cloud/tool/json-to-typescript-converter/
Paste a sample payload and get interfaces back, nested types included. It's a much faster starting point than typing them by hand. Just tighten the optional fields afterwards.
5. JSON ↔ YAML converters: for configs and CI files
- JSON to YAML: https://iotools.cloud/tool/json-to-yaml-converter/
- YAML to JSON: https://iotools.cloud/tool/yaml-to-json-converter/
Kubernetes manifests, GitHub Actions and OpenAPI specs all bounce between the two formats. The JSON→YAML converter also tolerates JSON5-style comments and trailing commas, which saves a cleanup step.
6. YAML Validator: find the indentation that broke the deploy
https://iotools.cloud/tool/yaml-validator/
It gives you the line and column of the error plus a structure summary (document count, top-level type, key counts). That's quicker than waiting for CI to fail.
7. JWT Decoder: read the token before you regenerate it
https://iotools.cloud/tool/jwt-decode/
Most 401s come down to exp, aud or iss. This decodes the header and payload and shows iat/nbf/exp as readable UTC times. It only inspects the token (it doesn't verify the signature), and the page says the token never leaves your browser.
If you just want a yes/no, there's also a JWT Expiry Checker: https://iotools.cloud/tool/jwt-expiry-checker/
8. Regex Tester (and Explainer): before it ships
- Tester: https://iotools.cloud/tool/regex-tester/
- Explainer: https://iotools.cloud/tool/regex-explainer/
The tester runs matches with the same JavaScript engine your front end uses, so there are no "works in PCRE, fails in JS" surprises. The explainer breaks a pattern down token by token. Run any regex you inherited from someone else through it first.
9. Hash Generator: check a checksum or webhook payload
https://iotools.cloud/tool/hash-generator/
MD5, SHA-1, SHA-256, SHA-512 and friends, computed locally with the open-source @noble/hashes library. It's useful for checking downloads and debugging signature mismatches. (The page itself reminds you to use Argon2 or bcrypt for passwords, not a fast hash.)
10. Base64 Decode + URL Encoder/Decoder: the encoding pair
- Base64 decode: https://iotools.cloud/tool/base64-decode/
- URL encode/decode: https://iotools.cloud/tool/url-encoder-decoder/
If an auth header, a webhook body or a query string looks like gibberish, it's usually one of these two, and sometimes both. There's even a ready-made chain for that: https://iotools.cloud/chains/base64-encode-then-url-encode/
11. Unix Timestamp Converter: is that 1728518400 in UTC or local?
https://iotools.cloud/tool/unix-timestamp-converter/
It converts both ways, handles seconds and milliseconds, and the FAQ confirms nothing you paste leaves your device. This is the tool I use most for reading logs.
12. Cron Expression Explainer: what does 0 */6 * * 1-5 actually mean?
https://iotools.cloud/tool/cron-expression-explainer/
Get a plain-English description plus the next run times. It's ideal for reviewing someone's scheduler PR without counting asterisks.
Bonus: UUID Generator
https://iotools.cloud/tool/uuid-generator/
v4, v7 (time-ordered, great for database keys) and more, in bulk, generated in your browser with a cryptographic RNG.
A quick way to check if a tool is client-side
Whichever site you use, open DevTools → Network, clear the log, paste your input and click the button. If no request goes out carrying your data, it's client-side. It takes ten seconds and is worth doing before you paste anything sensitive.
Grab them all in one place
If you want these in a side panel rather than a tab, the IO Tools browser extension puts 50 of them in Chrome, Edge, Firefox or Opera with no network calls: https://iotools.cloud/extension/
There's also a curated JSON workflow here: https://iotools.cloud/collections/work-with-json-data/
What's in your own "paste it somewhere safe" toolkit? I'd love suggestions for tools we're missing. And again, full disclosure: I'm on the IO Tools team, so feedback (including "this one's broken") goes straight to the people who can fix it.
Top comments (0)