DEVHOLSTER

All tools

Every tool on devholster on one page, grouped by category. 118 of them so far, all running in your browser tab, all free and without an account. If you already know what you are looking for, the search below beats scrolling.

118 tools.
7 categories.

Nothing you paste is uploaded, and once a tool has loaded it keeps working offline. Free, no signup.

.png Background Remover The background off any photo with BiRefNet on your GPU, in the tab. Full resolution, transparent or any colour, PNG or clipboard. .wav Speech to Text Dictate and the words appear while you speak, through the recogniser in your browser. Whisper in the tab for recordings, SRT export. .wav Text to Speech Read text aloud with every voice your system has, or with Kokoro on your GPU at podcast quality, saved as WAV. .srt Subtitle Generator Video or audio to SRT and WebVTT with Whisper in the tab. Cues wrapped to 42 characters, previewed on the video, translated to English on request. .yaml JSON to YAML Turn JSON into clean YAML for configs and pipelines. .json YAML to JSON Anchors and merge keys resolved on the way back to JSON. .toml JSON to TOML TOML configs for Cargo, pyproject and friends. .json TOML to JSON Cargo.toml or pyproject.toml as plain JSON. .xml JSON to XML JSON as XML, with the root element and attributes you pick. .json XML to JSON Feeds, SOAP and sitemaps parsed into JSON, attributes included. .xml YAML to XML YAML configs converted straight through to XML. .yaml XML to YAML Read an XML document as YAML, attributes preserved. .toml YAML to TOML Config migration: anchors resolved, nulls handled explicitly. .yaml TOML to YAML [[Sections]] become lists, dates stay real timestamps. .toml XML to TOML Legacy XML configs as TOML tables, attributes kept. .xml TOML to XML TOML into well-formed XML, dates as ISO 8601. .csv XML to CSV The repeated element becomes rows, attributes become columns. .xml CSV to XML Rows as elements, with root and row names you pick. .csv JSON to CSV Flatten nested API responses into Excel-ready CSV. .json CSV to JSON Spreadsheet exports become typed JSON arrays. .csv YAML to CSV The record list found anywhere in the tree, as clean rows. .yaml CSV to YAML Rows into a YAML list, ambiguous values safely quoted. .toml CSV to TOML Each row a [[table]], empty cells handled cleanly. .csv TOML to CSV [[Tables]] as spreadsheet rows, dates as ISO 8601. .tsv CSV to TSV Swap commas for tabs, quoting handled properly. .csv TSV to CSV Tab-separated exports back to RFC 4180 CSV. .md CSV to Markdown Table Paste a CSV, get an aligned Markdown table for the README. .csv Markdown Table to CSV Pull a Markdown table back out into CSV. .html CSV to HTML Table A ready-to-paste HTML table with thead and escaping. .sql CSV to SQL INSERT Rows become INSERT statements for your dialect. .xlsx CSV to Excel A real workbook: leading zeros, long IDs and umlauts survive. .csv Excel to CSV Any sheet of an .xlsx as clean UTF-8 CSV, dates as ISO. .csv Change CSV Delimiter Semicolon to comma and back, with the quoting redone. .epoch Unix Timestamp Converter Epoch to date and back, s/ms/µs/ns auto-detected, every zone, DST-correct. .txt Case Converter camelCase, snake_case, kebab-case and ten more, acronyms done right. .md Markdown to HTML Live preview, clean HTML, rich-text copy for Word and Gmail, TOC included. .sh cURL to Code Any curl command as fetch, Python requests, PHP or HTTPie code.
.txt Base64 Encode UTF-8 safe Base64, URL-safe variant and MIME wrapping included. .txt Base64 Decode Repairs padding, reads data URIs, hexdumps binary payloads. .b64 File to Base64 Any file as a Base64 string or data URI, read byte for byte. .png Image to Base64 Data URIs with ready-to-paste CSS and HTML snippets. .b64 Base64URL Converter The URL-safe alphabet JWTs use, encode and decode. .b32 Base32 Converter RFC 4648 Base32 both ways; TOTP setup keys paste as-is. .url URL Encode Percent-encode a single component or a whole URL. .url URL Decode Unpacks double encoding and names the broken byte. .html HTML Entities Encode Escape special characters, minimal or full table. .html HTML Entities Decode Full HTML5 entity table, output shown as text, never rendered. .jwt JWT Decoder Header, payload and claims read out, expiry as a real date. .tok LLM Token Counter Exact GPT token counts, coloured tokens, cost per model, JSON savings measured. .sql SQL Anonymizer Table, column and literal names swapped for placeholders, reversible with a key kept in your browser. .ts JavaScript Anonymizer JavaScript and TypeScript with your names as placeholders, npm imports and browser APIs kept, reversible. .py Python Anonymizer Modules, classes and functions as placeholders, the standard library kept, f-strings handled, reversible. .java Java Anonymizer Package chains, classes and methods as placeholders in the Java convention, JDK and Spring kept. .cs C# Anonymizer Namespaces, classes and properties as placeholders, LINQ and .NET kept, interpolated strings handled. .php PHP Anonymizer Classes, functions and $variables as placeholders with the sigil kept, Laravel and Symfony readable.
.key Password Generator Random passwords with honest entropy and crack-time math, offline. .id UUID Generator v4 and v7 in bulk, timestamps decoded, batches stay sorted. U+ Zero Width Space Copy One click copies exactly one U+200B or BOM, the paste field proves it. .dice Passphrase Generator Diceware words off the EFF list, with auditable dice rolls. .pin PIN Generator Random codes with the guessable ones filtered out, odds shown. .hash Bcrypt Generator Hash and check passwords, with the cost factor timed live. .sha256 SHA-256 Generator Hash text and files, verify checksums against an expected value. .sha512 SHA-512 Generator The long digest, with SHA-384 one flag away. .sha1 SHA-1 Generator Legacy checksums and Git object IDs, honestly labelled as broken. .md5 MD5 Generator The legacy checksum, computed in-page since browsers refuse it. .sig HMAC Generator Keyed hashes for webhook signatures, the secret never stored. .sql Supabase Query Generator SQL in, supabase-js out: joins as embeds, .or() strings, RPC fallback. .url Slug Generator Titles to clean URL slugs in bulk, umlauts and ł-class characters handled. .txt Lorem Ipsum Generator Filler text by words, sentences, paragraphs or exact characters. .cron Cron Expression Generator Click a schedule together, export it for crontab, k8s, GitHub Actions and systemd. .jwt JWT Generator Signed HS256, RS256 and ES256 test tokens, keys stay in your tab. .csv Test Data Generator Fake names, addresses and profiles, reproducible by seed. .iban IBAN Generator Valid test IBANs with correct check digits, bulk to 1000. .card Credit Card Test Numbers Official Stripe and Adyen test cards plus random Luhn-valid numbers. .txt robots.txt Generator Per-bot rules and a dated AI-crawler blocklist, validated.
.txt Invisible Character Detector Find and strip the hidden characters in text from AI chats, PDFs and Word. .txt AI Text Detector Scores AI writing patterns and highlights each one, honestly. .vec Semantic Similarity Checker Two texts scored by meaning with all-MiniLM-L6-v2 in your tab, both vectors drawn out, near-duplicates found in a list. .hdr Set-Cookie Parser Every cookie attribute explained, plus what browsers reject. .hdr Cache-Control Analyzer Who caches your response, for how long, and which directives fight. .re ReDoS Checker Times a regex against its own worst case, live in your tab. .yaml YAML Footgun Linter The values two YAML parsers read differently, named and quoted. .git gitignore Tester Which rule ignores which path, and why your negation does not fire. .cron Cron Expression Parser Crontab, Spring and Quartz in plain English, with next runs. .sql SQL Query Optimizer Query checked against your DDL: missing indexes named, rewrites included. .diff Text Diff Side by side or unified, and the invisible differences named. .json JSON Validator Every syntax error listed with line and fix, plus the ones JSON.parse hides. .hdr CSP Analyzer & Generator Every CSP weakness named with a fix, exported for nginx and Apache. .har HAR Analyzer Waterfall, timings and findings from a HAR export, tokens sanitised. .txt robots.txt Tester Which line blocks which URL, per bot, under RFC 9309 rules. .iban IBAN Validator All 89 registry countries, with the position that breaks a number. .vat VAT ID Validator EU VAT numbers checked offline, format and check digits. .num Luhn Checker The whole mod 10 calculation shown, check digits computed.
Your code stays on your machine.
Runs in your browser

The parsers ship with the page, so a tool keeps working after you go offline.

Instant, as you type

Every tool runs the moment you type. No run button, no waiting, nothing to install.

Free forever, no signup

No account, no paywall, no trial that expires. All 110+ tools, free for everyone.

Using web tools for real work

How can I tell whether an online tool uploads what I paste?

Open the network tab of your browser devtools, clear it, then use the tool and watch whether a request goes out while you type or when you press the button. A page that does the work locally makes no request at all beyond loading its own scripts. The stronger version of the test is to load the page, disconnect from the network and try again: anything that still works cannot have sent your input anywhere. A privacy policy is a promise, the network tab is evidence.

Is pasting company code into a web tool against policy?

In many organisations, yes, and the policy usually names the category rather than the site: source code, customer data and credentials must not be sent to third-party services without review. That is aimed at anything that transmits the input, which covers most online tools and every AI assistant, but not a page that computes in your own browser. Since the distinction is invisible from the outside, the defensible answer to a security review is a network capture, not a claim from the homepage.

When is a browser tool the wrong choice compared with a CLI?

When the file is large, when the job has to repeat, or when it has to run in CI. A browser tab holds the whole input in memory, so a multi-hundred-megabyte file belongs in a streaming command line tool, and anything that must run on every commit belongs in a script where it is versioned and reviewable. Web tools win for the one-off: a payload from a ticket, a config someone mailed you, a token you need decoded now, with nothing to install.