Data and security guide

Browser Utilities: JSON Repair, Streaming SHA-256, Base64 and Passwords

Use small developer and security utilities locally, with the distinction between encoding, hashing and encryption made clear.

By Dhruba PoudelReviewed 2026-09-29Tool runs at tools.dhrub.com.np

What can browser-native utility tools do without a server?

A modern browser can parse and format JSON, repair common JSON syntax mistakes, calculate a SHA-256 digest incrementally, encode or decode Base64 text, generate cryptographically strong random passwords and create UUIDs. Dhrub Free Tools keeps repair and hashing in background workers: repaired text is shown as a preview until you explicitly apply it, and files are read in small chunks instead of one whole-file buffer.

How to use the tool

Choose the operation

Select JSON, file hash, Base64 or password and UUID generation.

Provide the minimum input

Paste text or choose only the file needed for the operation.

Review before applying

Compare a repair preview or expected digest before accepting or copying the result.

At a glance

File digest
Incremental SHA-256 in 4 MB chunks
JSON repair
Preview first; input changes only after confirmation
Base64
Encoding, not encryption
Random passwords
Web Crypto random values
UUID generation
Browser randomUUID where supported

Hashing, encoding and encryption are different

A SHA-256 digest is a fixed-length fingerprint useful for checking whether two copies of a file are identical. It does not hide the file and cannot prove who created it unless the expected digest came through a trusted channel. The local worker reads at most one 4 MB slice at a time, updates the digest, and reports progress rather than copying the whole file into memory.

Base64 represents binary data using text characters. Anyone can decode it, so it must not be used to conceal passwords or private records. Encryption requires a separate algorithm, key-management process and threat model.

  • Label hashes with the algorithm name: SHA-256.
  • Use the expected-hash field to compare all 64 hexadecimal characters from a trusted source.
  • Use a password manager to store generated passwords.
  • Do not include secrets in a URL or QR code merely because they are Base64-encoded.

JSON and large files

JSON formatting validates syntax and changes whitespace; it does not validate whether the data matches an application’s expected schema. The optional doctor can repair common issues such as missing quotes, trailing commas and Python-style literals, but its result is only a candidate. It appears in a separate read-only preview and never silently overwrites the input.

Repair runs in a disposable worker with conservative character, nesting-depth and elapsed-time limits. These controls keep malformed or adversarial input from holding the interface indefinitely, but they do not turn repaired data into trusted data.

Important limitations

  • JSON formatting checks syntax, not business rules or schema correctness.
  • Automatic JSON repair can change meaning; inspect the preview before applying it.
  • SHA-256 verifies byte equality only when the expected hash is trustworthy.
  • Base64 does not provide secrecy, integrity or authentication.
  • The browser workflow retains a conservative 100 MB file limit even though hashing is incremental.

Questions people ask

Can I reverse a SHA-256 hash?

No practical reverse operation is provided. A hash is not encryption; weak passwords can still be guessed by hashing candidate values.

Is Base64 safe for passwords?

No. Base64 is openly reversible and should be treated as plain text.

Are browser-generated passwords secure?

The generator uses the browser’s cryptographically secure random source. Security still depends on sufficient length, unique use and safe storage.

Will JSON repair overwrite my text?

No. Repair creates a separate preview. The input changes only when you choose “Use repaired JSON as input”.

Primary and project sources

  1. Web Cryptography API — W3CStandard for browser digest and cryptographic primitives.
  2. Base-N Encodings — RFC Editor / IETFNormative Base64 encoding specification.
  3. UUIDs — RFC Editor / IETFCurrent UUID specification.
  4. JSON data interchange format — RFC Editor / IETFNormative JSON specification.
  5. @noble/hashes project — Paul Miller and contributorsAudited MIT-licensed incremental SHA-256 implementation used in the checksum worker.
  6. jsonrepair project — Jos de Jong and contributorsISC-licensed JSON repair library used inside a bounded worker.