開発者向けセキュリティツールガイド

Free ハッシュ · HMAC · AES · RSA · JWT · パスワード No signup · No data stored · Works offline

このガイドで紹介するツール

Hash Generator
MD5, SHA-1, SHA-256, SHA-512 & more
HMAC Generator
HMAC-SHA256 for API and webhook signing
AES Encrypt & Decrypt
AES-128/192/256 browser-based encryption
RSA Encrypt & Decrypt
RSA-OAEP 2048/4096-bit key pairs
JWT Decoder
Inspect header, payload and expiry
Password Generator
Cryptographically secure random passwords
Base64 Encoder
Encode binary data and key material
URL Encoder
Percent-encode query parameters
Last updated: March 2026  ·  v1.0
Quick Answer
What are the key cryptographic tools every developer needs?

Developers regularly need hashing, signing, encryption and token inspection. The 5 most important rules:

  1. Never use MD5 or SHA-1 for security — they are cryptographically broken. Use SHA-256 minimum.
  2. Never use SHA-256 for passwords — it is too fast. Use bcrypt, scrypt or Argon2.
  3. HMAC ≠ hash — HMAC requires a secret key, plain hashes do not prove authenticity.
  4. Use AES for data at rest, RSA for key exchange — never RSA for bulk data (1000× slower than AES).
  5. JWT payloads are not encrypted by default — they are only signed; never put sensitive data in a JWT without JWE.

Security operations — hashing a payload, signing an API request, encrypting sensitive data, decoding a JWT — are part of daily developer work. Having fast, reliable browser-based tools for these operations means you can inspect and verify security artifacts without setting up local environments or uploading sensitive data to unknown servers.

Hashing: MD5 vs SHA-1 vs SHA-256 vs SHA-512

A hash function takes an input of any size and produces a fixed-size output (the digest). The same input always produces the same output; even a single character change produces a completely different digest.

MD5 produces a 128-bit (32 hex character) digest. It is fast but cryptographically broken. Use MD5 only for checksums where collision resistance is not required, such as detecting accidental file corruption or cache invalidation keys.

SHA-1 produces a 160-bit digest. Also considered broken since 2017 (the SHAttered attack). Avoid SHA-1 for new security-critical code.

SHA-256 (part of the SHA-2 family) produces a 256-bit digest and is the current standard for security-critical hashing. Used in TLS certificates, code signing, and most modern authentication systems.

SHA-512 produces a 512-bit digest. On 64-bit processors, SHA-512 is often faster than SHA-256 due to its internal word size matching the processor's native width.

HMAC: signing API requests and webhooks

HMAC (Hash-based Message Authentication Code) adds a secret key to a hash, producing a signature that proves both the content and the sender's identity.

AWS Signature v4 uses HMAC-SHA256 to sign every API request. The signature covers the HTTP method, URL, headers, and body hash, preventing any tampering in transit.

Stripe and GitHub webhooks include an X-Stripe-Signature or X-Hub-Signature-256 header containing an HMAC-SHA256 of the request body. Your server recomputes this with your webhook secret and rejects requests where the signatures don't match.

JWT HS256 uses HMAC-SHA256 to sign the token header and payload. Use our HMAC Generator to compute and verify HMAC signatures during development and debugging.

AES vs RSA: symmetric vs asymmetric encryption

AES (symmetric) uses the same key to encrypt and decrypt. It is extremely fast — modern CPUs have hardware instructions for AES achieving multi-gigabyte throughput. AES-256 is used for encrypting data at rest: database fields, file encryption, disk encryption.

RSA (asymmetric) uses a public key to encrypt and the corresponding private key to decrypt. RSA is much slower than AES (1000x or more for bulk data), so it is typically used only to encrypt a small AES key, which then encrypts the actual data (hybrid encryption, as used in TLS).

Padding matters: Never use raw RSA without padding. RSA-OAEP (Optimal Asymmetric Encryption Padding) is the secure standard. Our RSA Encrypt & Decrypt tool uses RSA-OAEP exclusively.

JWT tokens: structure, claims, and common issues

A JWT (JSON Web Token) consists of three Base64url-encoded parts separated by dots: header, payload, and signature.

Header: Specifies the algorithm. {"alg": "HS256", "typ": "JWT"} means HMAC-SHA256 signing. RS256 means RSA-SHA256.

Payload: Contains claims — standard claims include sub (user ID), iss (issuer), exp (expiration Unix timestamp), and iat (issued at).

The none algorithm vulnerability: Some JWT libraries accept {"alg": "none"}, bypassing signature verification entirely. Always verify the algorithm on your server and reject tokens with unexpected algorithms.

JWTs are not encrypted by default: A standard JWT is signed but not encrypted — anyone who intercepts it can read the payload. Never put sensitive data in a JWT payload unless you use JWE.

Frequently asked questions about developer security tools

パスワードのハッシュ化に SHA-256 を使えますか?

いいえ。SHA-256 は高速な汎用ハッシュのため、パスワードを総当たりしやすくなります。代わりに bcrypt、scrypt、Argon2 を使ってください。これらは意図的に遅く、メモリを多く消費するよう設計されています。パスワードジェネレーターは強力なパスワードを生成しますが、保存はサーバー側で bcrypt/Argon2 を使うべきです。

エンコードと暗号化の違いは何ですか?

エンコード(Base64 など)は互換性のためにデータを変換するもので、鍵なしで元に戻せます。暗号化(AES など)は機密性を守るもので、正しい鍵がなければ元に戻せません。Base64 をセキュリティ対策として使ってはいけません。

JWT が期限切れかどうかを確認するにはどうすればよいですか?

JWT デコーダーを使ってください。トークンを貼り付けると、ツールが exp クレームを読み取り、期限切れ/有効を示すわかりやすいインジケーターとともに有効期限を表示します。

ブラウザーでパスワードを生成しても安全ですか?

はい、crypto.getRandomValues() を使う場合は安全です。パスワードジェネレーターはこれを使っています。これはブラウザーの CSPRNG で、オペレーティングシステムが鍵生成に使うのと同じエントロピー源です。

AES の鍵サイズはどれを使うべきですか?

新規のアプリケーションにはすべて AES-256 を使いましょう。AES-128 も既知の攻撃に対しては技術的に安全ですが、AES-256 はより大きな安全マージンを提供します。最新のハードウェアではパフォーマンスの差はごくわずかです。