Choose a format in Settings, then drop a file into File Encode. You can also use the file picker. For folders, drag the folder into the drop area. ZIP All collects encoded results when you have more than one file.
Show file hashes adds MD5 and SHA-family digests. Hashes describe the bytes being encoded, after any accepted resize or compression. MD5 and SHA-1 are compatibility checks, not modern security guarantees.
Compress before encoding uses gzip only when it saves enough space. Already-compressed media is skipped. Include Data URI prefix is available for standard Base64. Split Output controls JSON export chunks, not independent decoded files.
The app reads files into memory. Above 50 MiB, compatible encodings use chunked worker messages, but the complete input and output still occupy memory. Start with small files. Base58 and Base62 use large-integer arithmetic and can be slow.
Image resizing keeps the aspect ratio and doesn't enlarge an image. Export support depends on the browser; an unavailable AVIF encoder produces an error rather than a mislabeled image. Hashes and MIME details refer to the converted output.
Code snippets are examples, not automatic uploads. Review the destination and whether the snippet expects binary data, a data URI or encoded text before using it. QR export either encodes the whole result or reports that it cannot fit. The download is a GIF image.
Open Text, choose Encode or Decode, and enter a value. Results update as you type. Convert runs the same operation immediately. Per line processes each nonempty line independently.
Supported text formats are Base64, Base64URL, Hex, URL encoding, UTF-7 and IMAP UTF-7. The extra file formats are not text decoders. The font picker uses fonts already installed on your device.
Decode reads standard or URL-safe Base64. It accepts whitespace and a data URI prefix. Preview handles recognized image, audio and video formats; text can be inspected with Hex Dump or the Text tab.
Validate & Repair offers a proposed repair. Review it before applying it. Removing an invalid character cannot recover a missing original byte. Format detection and nested decoding are heuristics, not reliable identification of arbitrary data.
Entropy is a statistical description of a byte sample. It does not prove that a file is compressed, encrypted or safe.
The PEM tools wrap or unwrap encoded bytes and inspect supported certificate/key structures. They don't validate certificate chains or trust. DNS TXT output is a draft to review against your DNS provider and mail configuration, not a deployment or delivery test.
Paste a sample token in JWT. The header and payload are readable without a secret. Not expired describes the expiry claim only. It doesn't mean the token is authentic or authorized.
Verify Signature supports HS256, HS384 and HS512 when you supply the HMAC secret. Other signing algorithms can be displayed but cannot be verified here. A matching signature alone does not validate issuer, audience or your application's authorization policy.
The release ZIP includes the application and its two libraries. Extract everything before opening index.html. Do not open it inside the ZIP viewer. File-based use doesn't install a service worker.
For installation, serve the app over HTTPS or localhost and use a supporting browser's install control. Keep the app open until the first load finishes before disconnecting. Browser storage can be evicted, and clearing site data removes local history and caches. Keep a copy of the ZIP for dependable disconnected access.
The Web Share Target depends on platform support. Sharing text can put that text into a local app URL. Shared files are temporarily stored in the app's browser cache until the receiving page consumes them. Don't use OS sharing for sensitive material on a shared computer.
File history is enabled by default. It is a convenience preview, not a backup. Large results are truncated in history. Use the file download for complete output. Clear history separately from the current file list.
The hosted app's page request goes to GitHub Pages. Fetch contacts the URL you enter and is subject to CORS. Share and Copy Link are deliberate export actions. Links expose their encoded contents to anyone who can read the URL, including browser history and potentially hosting logs.