Client-Side Crypto Tools
Inspect JWTs, generate secure passwords, and compute checksums locally — nothing is uploaded to RookVPN.
Developer and IT workflows often paste tokens into random websites. RookVPN hosts browser-only utilities so sensitive material never transits our servers.
RookJWT — decode and verify tokens
URL: rookvpn.com/jwt
- Decode: Paste an access token to inspect header and payload JSON (issuer, audience,
exp, scopes). Useful when debugging OAuth flows with RookAuth or third-party APIs. - Verify: Provide the public key or shared secret and confirm signature algorithm alignment (HS256, RS256, etc.) using the Web Crypto stack.
Tokens are processed entirely in JavaScript in your tab. Close the tab when finished — browser memory is not a vault.
RookPass — passwords and breach checks
URL: rookvpn.com/pass
- Generate random passwords with
crypto.getRandomValues(notMath.random). - Build diceware-style passphrases from the EFF word list for memorable high-entropy phrases.
- Optional Have I Been Pwned k-anonymity lookup: only a hash prefix leaves the browser.
Use generated passwords with your password manager; RookPass does not store them.
RookHash — checksums and bcrypt
URL: rookvpn.com/hash
- SHA-256 / SHA-512 for strings and local files dropped into the page.
- Bcrypt with configurable cost for testing auth backends.
- RSA key pair generation for lab environments (keys never leave the device).
Ideal for verifying download checksums or reproducing password hashes during development — not for production key ceremony.
Security habits
- Never paste production refresh tokens on shared screens.
- Prefer offline air-gapped tools for long-lived private keys; RookHash RSA mode is for convenience, not HSM replacement.
- Pair JWT debugging with VPN leak tests when testing auth from untrusted networks.
Related
- JWT decoder guide
- Password generator guide
- Hash generator guide
- Subnet calculator guide
- Online curl tool guide for API testing without local curl
Check the result
Decode a JWT and then verify it. A decoded payload is not a signature. Hash a file with the algorithm the publisher printed, not the algorithm you prefer. Generate a password and put it in a manager before you close the tab.
The longer guides are JWT, passwords, and hashes. Use those when you are changing server code or a storage scheme, not only when you need a box to paste into.