Security Toolkit
5 security utilities in one tool: HMAC generator, RSA key pair generator, API key/secret token generator, password strength analyzer, and Luhn/card checksum validator — all computed locally in your browser via the Web Crypto API.
- Pick a mode from the pill bar: HMAC Generator, RSA Key Pair, API Key Generator, Password Strength, or Luhn Validator.
- For HMAC, enter your message and secret key and choose a hash algorithm — the hex and base64 digest recompute instantly as you type.
- For RSA, choose 2048 or 4096-bit, click Generate, and copy the public/private PEM blocks immediately (nothing is saved after you navigate away).
- For token generation, password analysis, or checksum validation, type or paste your input and the result updates live — nothing is ever transmitted anywhere.
All processing happens entirely in your browser. Your data never leaves your device.
Key Features
- HMAC generator supporting SHA-1, SHA-256, SHA-384, and SHA-512, with hex and base64 output
- RSA key pair generator (2048 or 4096-bit) producing standard PEM-encoded public and private keys
- API key / secret token generator with alphanumeric, hex, and URL-safe base64 charsets plus an optional prefix
- Live entropy-bits estimate for generated tokens
- Password strength analyzer with a 5-level meter, common-password detection, and sequential/repeated pattern checks
- Luhn checksum validator with automatic card network detection (Visa, Mastercard, Amex, Discover)
- Every computation runs locally via the Web Crypto API — nothing is ever transmitted or stored
- One-click copy buttons on every generated value
About Security Toolkit
Developers reach for small cryptographic and security utilities constantly: signing a webhook payload with HMAC, generating a key pair to test a signing flow, spinning up a random API secret, sanity-checking a password policy, or validating that a card/ID number is at least checksum-correct before wasting an API call on it. Usually that means pulling in a library, writing a quick script, or worse, pasting a secret into some random website.
The Security Toolkit bundles five of these everyday utilities into a single client-side tool built on the browser's native Web Crypto API. HMAC (Hash-based Message Authentication Code) proves a message came from someone holding a shared secret and hasn't been tampered with — it's the backbone of webhook signature verification (Stripe, GitHub, etc.) and signed API requests. RSA key pairs use asymmetric cryptography for signing and encryption, exported here as standard PEM-encoded SPKI/PKCS8 blocks you can drop straight into other tools. The API key generator produces cryptographically random tokens using crypto.getRandomValues, the same secure random source used by the Secure Password Generator elsewhere in ForgeKit.
Everything — key generation, signing, entropy estimation, and validation — runs entirely in your browser tab. No message, secret, password, or card number is ever sent to a server, logged, or stored. The Luhn checksum validator is a format check only (used by card numbers, IMEIs, and many ID schemes) — it confirms a number is structurally valid, never that an account is real or funded.
Frequently Asked Questions
No. Every operation in this toolkit — HMAC signing, RSA key generation, token generation, password analysis, and Luhn validation — runs entirely inside your browser using the Web Crypto API and JavaScript's crypto.getRandomValues. Nothing is transmitted to a server or stored.
SHA-1, SHA-256, SHA-384, and SHA-512, selectable from a dropdown. SHA-256 is the most common choice for modern webhook signature verification (e.g. Stripe, GitHub).
Yes — they're generated using the browser's native Web Crypto API (crypto.subtle.generateKey), the same underlying implementation used by browser TLS and WebAuthn. Nothing is saved after generation, so copy both PEM blocks immediately; refreshing or generating a new pair discards the old one permanently.
No. It only validates the Luhn checksum, a mathematical format check used by card numbers, IMEIs, and various ID schemes. It cannot and does not verify that a card is real, active, or has any balance.
2048-bit is the current industry-standard minimum and is fast to generate. 4096-bit offers a larger security margin at the cost of slower generation (a couple of seconds) and larger keys — use it if your target system specifically requires it.