Client-Side Crypto Tools

Inspect JWTs, generate secure passwords, and compute checksums locally — nothing is uploaded to RookVPN.

Developer and IT workflows often paste tokens into random websites. RookVPN hosts browser-only utilities so sensitive material never transits our servers.

RookJWT — decode and verify tokens

URL: rookvpn.com/jwt

Tokens are processed entirely in JavaScript in your tab. Close the tab when finished — browser memory is not a vault.

RookPass — passwords and breach checks

URL: rookvpn.com/pass

Use generated passwords with your password manager; RookPass does not store them.

RookHash — checksums and bcrypt

URL: rookvpn.com/hash

Ideal for verifying download checksums or reproducing password hashes during development — not for production key ceremony.

Security habits

  1. Never paste production refresh tokens on shared screens.
  2. Prefer offline air-gapped tools for long-lived private keys; RookHash RSA mode is for convenience, not HSM replacement.
  3. Pair JWT debugging with VPN leak tests when testing auth from untrusted networks.

Check the result

Decode a JWT and then verify it. A decoded payload is not a signature. Hash a file with the algorithm the publisher printed, not the algorithm you prefer. Generate a password and put it in a manager before you close the tab.

The longer guides are JWT, passwords, and hashes. Use those when you are changing server code or a storage scheme, not only when you need a box to paste into.