About
What this site is, why it exists, and how the tools are built.
What this site is
Tooleux is a collection of 241 browser-based utilities for developers, security engineers, and anyone who works with data formats. Hashing, encoding, encryption, compression, formatting, conversion - the routine tasks that come up when you are working on a system and need a quick, reliable answer.
Every tool runs entirely in your browser. Nothing is uploaded. No accounts, no tracking, no paywalls.
Why this site exists
Most "free online tool" sites have the same shape: you paste something, it gets uploaded to a server, an ad-laden result page comes back, and you have no idea what happened to your input. For routine work that is an unnecessary privacy trade-off. For anything sensitive - a private key, a contract, a patient record - it is a non-starter.
This site was built on a different premise: the browser is a capable enough execution environment for almost every tool in this category. Hashing a file, encrypting a message, converting JSON - none of it requires a server. If the computation can happen locally, it should happen locally.
What makes it different
No uploads, ever. Files and text stay on your device. You can verify this: open your browser's developer tools, switch to the Network tab, use any tool, and watch no requests fire after the page loads.
Analytics, used honestly. The site uses Google Analytics 4 to measure page views. It never sees your tool input, and it is disclosed in full in the privacy policy.
No accounts. You cannot log in because there is nothing to log in to. The only things stored on your device are preferences you explicitly set.
No ads (currently). Every page loads without advertising. If that changes, it will be disclosed on this page and in the privacy policy before any ads are shown.
Real documentation. Each tool page explains what the algorithm is, when to use it, and what the trade-offs are. Most include a command-line equivalent. If you are learning what KMAC128 is for, the page should teach you, not just compute for you.
Editorial standards
The tools here follow four rules:
- Correctness first. If a tool says SHA-256, it produces the NIST-standard SHA-256. If it says Argon2id, it produces Argon2id. No approximations. Where a standard publishes test vectors, those vectors are checked in the automated test suite before every build.
- Real dependencies, not hand-rolled code. Cryptographic primitives come from established libraries - @noble/hashes, hash-wasm, @noble/ciphers, jose, and the Web Crypto API. Nothing cryptographic is invented here.
- Honest labeling. Algorithms that are broken for new use (RC4, DES, MD5, MD2, MD4) say so on the page. Legacy compatibility is stated as legacy compatibility, not as a feature.
- No dark patterns. No "sign up to unlock." No email harvesting disguised as a feature. No artificial limits.
Tested, and open to inspection
Every tool is verified by an automated test suite that runs before every deployment. The suite loads every page, exercises the example input, and asserts that the tool produces output rather than an error. Tools that implement published standards are checked against their known-answer vectors.
The rendered JavaScript of any tool is inspectable in your browser: open DevTools, go to the Sources tab, and read the code. If you find a discrepancy between a tool's output and a reference implementation, that is a bug - please report it. You can also view live test results on the verification page.
Who runs this
Tooleux is a solo project maintained by Igewale Victor. It started as an internal set of scripts and grew into what you are looking at now. Bug reports, corrections, and tool suggestions are all welcome - see the contact page.
How it is funded
The site is free to use. There is no paid tier, no subscription, and no feature behind a paywall. Every tool is available without an account.
If advertising is introduced in the future, this page and the privacy policy will be updated to disclose it before any ads are shown.
If the site ever adds advertising or a paid feature, this page and the privacy policy will be updated first. Users will never be surprised by a change in that direction.
What this site does not do
- It does not upload your files or text to any server.
- It does not log your IP address or identify you. (The hosting provider logs requests as a matter of course - see the privacy policy for details.)
- It does not sell, share, or trade any data.
- It does not require registration, a login, or an email address.
- It does not show interstitial ads, pop-ups, or overlays of any kind.
- It does not fingerprint your browser.
Related reading
- Security and architecture - how the browser-only model works
- Privacy policy - what data is and is not collected
- Terms of service
- FAQ - common questions about using the site