Password Generator
Create strong, secure passwords with customizable rules.
25 tools. Password generators, hash tools, encryption, and security analyzers.
Generate a strong secret, then test the ones you already use.
Create strong, secure passwords with customizable rules.
Generate secure random keys for APIs and encryption.
Analyze password security and get improvement suggestions.
Check if your passwords have been exposed in known data breaches using k-Anonymity.
Validate passwords against custom patterns, common passwords, and entropy requirements.
Hash text or a file, sign a payload, and compare digests.
Generate MD5, SHA-1, SHA-256 hashes from text.
Generate HMAC signatures for message authentication.
Calculate MD5, SHA-1, SHA-256, SHA-512 checksums for files.
Compare file or text hashes to verify integrity using SHA-256, SHA-512, and more.
Hash a password with bcrypt or Argon2id for storage, or verify a password against a stored hash, in your browser.
Encrypt a message, share a note inside a link, test a 2FA code.
Encrypt and decrypt text using AES-256 encryption.
Generate RSA key pairs as PEM and encrypt or decrypt a short message with RSA-OAEP. Not OpenPGP.
Create encrypted, self-destructing notes with password protection and expiration.
Test and verify TOTP two-factor authentication codes from your authenticator app.
Validate an address or a phone number before you store it.
Validate email addresses for proper format and syntax.
Verify email domain security with SPF, DKIM, DMARC, and MTA-STS checks.
Validate and format phone numbers from any country with E.164 and international formats.
Strip metadata, redact data, and audit what a site sets on you.
Remove metadata from photos to protect your privacy. Strip GPS, camera info, and timestamps.
Strip the author, company, template and editing history a Word document carries in its properties, without uploading the file.
Sanitize user input for HTML, SQL, XSS, and other security threats.
Analyze URLs for potential security threats and phishing indicators.
Analyze browser cookies for security attributes like Secure, HttpOnly, and SameSite.
Build a Content-Security-Policy header from presets and directives, with a meta tag and warnings for unsafe sources.
Analyze privacy policies for data collection, user rights, and compliance issues.
Generate .reg files, PowerShell scripts, and batch files to control Windows Update behavior. Disable auto-updates, block restarts, manage driver updates.
Security · 8 min
How to Write a Content-Security-Policy Header, Step by StepSecurity · 8 min
bcrypt vs Argon2id: How to Hash a Password for StorageSecurity · 7 min
JWT Generator: Create Signed JSON Web Tokens OnlineSponsor FindUtils
Every request is reviewed by a person. You get an exact quote before anything goes live.
About this category
FindUtils provides 25 browser-based security tools for password generation and strength checks, MD5 and SHA hashing, HMAC signatures, AES text encryption, 2FA code testing, and removing metadata from documents and photos. The generators and encoders use the Web Crypto API and run in your browser. The two tools that have to reach the network say so on the page, and neither sends your secret: the password breach checker and the email security checker. To decode or verify JWT tokens, use the JWT Decoder in Developer Tools; to check SSL certificates or HTTP security headers, use the Network tools. FindUtils.com is not the GNU findutils package.
Almost entirely, and where it is not, the page says so. Passwords you generate, text you encrypt and hashes you compute are handled in your browser with JavaScript and the Web Crypto API, and are never sent anywhere. Two tools have to reach the network to do their job, and neither sends your secret: the password breach checker uses the k-anonymity method, sending only the first five characters of your password's SHA-1 hash to Have I Been Pwned so the password itself never leaves your device, and the email security checker looks up public DNS records for the domain you enter. Anything you paste into the other tools stays local, which you can confirm by watching your browser's network tab. These pages also load third-party analytics and advertising scripts, which see the page you are on but not what you type.
The FindUtils password generator uses the Web Crypto API's crypto.getRandomValues() function, which provides cryptographically secure pseudo-random number generation (CSPRNG). This is the same entropy source used by browsers for TLS/SSL connections and is considered secure for generating passwords, tokens, and cryptographic keys. The generator runs locally in your browser with no server communication. You can customize password length from 4 to 128 characters and select character sets including uppercase, lowercase, numbers, and special symbols. The tool also displays real-time password strength analysis using the zxcvbn algorithm, showing estimated crack time and entropy bits for each generated password.
For text, the hash generator computes MD5, SHA-1, SHA-256 and SHA-512 at once, and the hash comparison tool checks a value against MD5, SHA-1, SHA-256, SHA-384 or SHA-512. The HMAC generator signs a message with a secret key using SHA-1, SHA-256, SHA-384 or SHA-512. The file hash calculator reads a file in your browser and gives its MD5, SHA-1, SHA-256 and SHA-512 checksums, which you can compare against a published value to confirm a download was not changed. The SHA family uses the browser's built-in Web Crypto API; MD5, which Web Crypto does not offer, runs in a small JavaScript implementation. Results are shown in hexadecimal. Use MD5 and SHA-1 only for checksums, not for security, and use a slow password hash such as bcrypt or Argon2 to store passwords.
Yes. The FindUtils password breach checker uses the Have I Been Pwned (HIBP) API with a k-anonymity privacy model. When you enter a password to check, the tool computes its SHA-1 hash locally in your browser, then sends only the first 5 characters of the hash prefix to the HIBP API. The API returns all known breached password hashes that share that prefix, and your browser checks locally whether your full hash appears in the returned set. This means your actual password, and even its complete hash, is never transmitted over the network. Have I Been Pwned is a widely used public database of passwords exposed in data breaches. The API path is different: see the tool page for what an API call sends.
Categories people open next.
From FindUtils
Products and services from the team behind FindUtils.
<link rel="icon" href=".../🦊.svg"> Create a favicon