P
Guides
Language
Tools
Password & Security
P
Password Strength Checker
Score any password and estimate crack time
P
Password Generator
Create strong random passwords up to 128 chars
R
Random String Generator
Random tokens, IDs and keys with any charset
P
Passphrase Generator
Memorable multi-word passphrases (Diceware)
T
TOTP / 2FA Code Generator
Time-based one-time codes and otpauth secrets
P
Password Breach Checker
Check if a password appeared in known breaches
Hash & Crypto
S
SHA-256 Generator
Hash text to a 64-char SHA-256 digest
M
MD5 Generator
Compute the 32-char MD5 checksum of any text
S
SHA-1 Generator
Generate the 40-char SHA-1 hash of any input
S
SHA-512 Generator
Hash text to a 128-character SHA-512 digest
H
HMAC Generator
HMAC-MD5, SHA-1, SHA-256 & SHA-512 with secret key
B
bcrypt Generator / Checker
Hash passwords with bcrypt and verify hashes
P
PBKDF2 Key Derivation
Derive keys from a password with salt and iterations
A
AES Encrypt / Decrypt Text
Encrypt text with AES-256-GCM and a password
F
File Hash / Checksum
Compute SHA hashes of any file locally
Networking
I
IP Address Checker
Identify IPv4 vs IPv6, public/private and more
I
IPv4 Calculator
Network, broadcast, hosts, subnet mask & wildcard
I
IPv6 Calculator
Expand, compress and subnet IPv6 addresses
S
Subnet Calculator
CIDR ranges, wildcard masks and usable hosts
M
MAC Address Generator
Random valid MAC addresses, unicast or multicast
P
Port Checker
Learn what each TCP/UDP port number means
D
DNS Lookup
Resolve A, AAAA, MX, NS, TXT and CNAME records
W
WHOIS Lookup
Domain registration, expiry and registrar info
Web & HTTP
H
HTTP Header Analyzer
Security, caching & SEO headers explained
U
User-Agent Parser
Decode browser, OS and device from any UA
M
MIME Type Lookup
File extension to MIME type reference
H
HTTP Status Code Lookup
Every status code 1xx–5xx explained
U
URL Encoder / Decoder
Percent-encode URLs and parse query strings
C
Color Contrast Checker (WCAG)
Check text contrast against WCAG AA & AAA
Developer Utilities
U
UUID / ULID Generator
UUID v4, v7, ULID and NanoID in bulk
J
JWT Decoder & Signer
Decode, inspect and sign JSON Web Tokens
B
Base64 Encoder / Decoder
Encode and decode Base64, standard or URL-safe
Q
QR Code Generator
QR codes for links, Wi-Fi and vCards
J
JSON Formatter & Validator
Format, minify and validate JSON instantly
T
Unix Timestamp Converter
Convert Unix timestamps to dates and back
R
Regex Tester
Test regular expressions with live matches
D
Diff Checker
Compare two texts and highlight differences
L
Lorem Ipsum Generator
Placeholder paragraphs, sentences or words
N
Number Base Converter
Convert between binary, octal, decimal and hex
C
Color Converter (HEX / RGB / HSL)
Convert colors and copy HEX, RGB or HSL
C
CSV to JSON Converter
Convert CSV to JSON and JSON back to CSV
C
Case Converter & Slug Generator
camelCase, snake_case, kebab-case, Title & slug
W
Word & Character Counter
Words, characters, sentences and reading time
Security

Hashing vs Encryption vs Encoding

Three words that get used interchangeably and should not be. Each solves a different problem — mixing them up is a security bug.

Updated 16 September 2026 · 8 min read
Advertisement

Three different jobs

Technique Reversible? Key? Purpose
Encoding Yes No Data transport
Encryption Yes Yes Confidentiality
Hashing No No Integrity / verification

Mixing up the columns is where security bugs come from.

Encoding

Encoding transforms data into another representation for transport or storage — and back. It provides no security.

  • Base64 — binary as text.
  • URL encoding — safe characters for URLs.

Try the Base64 encoder/decoder. Never use encoding to protect secrets.

Encryption

Encryption scrambles data so only someone with the key can read it. It is reversible by design.

  • Symmetric (AES) — one shared key, fast.
  • Asymmetric (RSA, ECC) — public/private key pair.

Use it for confidentiality: data at rest, HTTPS, messaging. Manage keys carefully; encryption is only as strong as key handling.

Hashing

Hashing produces a fixed-length digest from any input. It is one-way — you cannot reverse it.

  • Integrity — detect changes.
  • Signatures — sign a digest, not the data.
  • Password storage — with a salt and slow algorithm.

Compute digests with the SHA-256 generator and keyed hashes with the HMAC generator.

The password trap

Storing passwords with fast hashes (MD5, SHA-256) is a mistake: attackers can try billions of guesses per second. Correct approach:

  1. Salt each password uniquely.
  2. Use a deliberately slow algorithm — bcrypt, scrypt or Argon2.
  3. Never reuse the same hash across users.

HMAC: hashing with a key

HMAC combines a hash with a secret key to authenticate a message. It verifies both integrity and authenticity — used in webhooks, API signatures and JWTs.

Quick decision guide

  • Needed back, no secrecy → encoding.
  • Needed back, secrecy required → encryption.
  • Never needed back, verify integrity → hashing.

Use the right tool

All three run locally in your browser with these free tools — your data never leaves your device.

Advertisement
Help Center

Hashing vs Encryption vs Encoding — FAQ

No. Hashing is one-way and irreversible; encryption is reversible with a key. You cannot decrypt a hash.

No. Base64 is encoding, not protection. Anyone can decode it. It offers zero confidentiality.

A slow, salted password hash such as bcrypt, scrypt or Argon2 — never encryption, never a fast hash like SHA-256.

Keep reading
Advertisement