POST/v1/hash1 credit / call
Hash generator
Compute MD5, SHA-1, SHA-224/256/384/512 and SHA3-256/512 digests of the given text.
| Parameter | Type | Required | Description |
|---|
| text | string | Yes | Text to hash. |
Request
curl -X POST https://toolsonduty.com/api/v1/hash \
-H "Authorization: ******" \
-H "Content-Type: application/json" \
-d '{"text":"hello"}'
Response
{
"ok": true,
"data": {
"sha256": "2cf24dba5fb0a30e26e83b2ac5b9e29e1b161e5c1fa7425e73043362938b9824"
}
}
POST/v1/password1 credit / call
Random password generator
Generate a random password from the selected character sets.
| Parameter | Type | Required | Description |
|---|
| length | number | No | Password length (1-128). Default: 16. |
| lower | boolean | No | Include lowercase letters. Default: true. |
| upper | boolean | No | Include uppercase letters. Default: true. |
| numbers | boolean | No | Include digits. Default: true. |
| symbols | boolean | No | Include symbols. Default: true. |
| noAmbiguous | boolean | No | Exclude look-alike characters (O/0, l/1, ...). Default: false. |
Request
curl -X POST https://toolsonduty.com/api/v1/password \
-H "Authorization: ******" \
-H "Content-Type: application/json" \
-d '{"length":20}'
Response
{
"ok": true,
"data": {
"password": "kP9#mZ2qT7vR...",
"entropyBits": 130
}
}
POST/v1/security/base581 credit / call
Base58 encode / decode
Encode text to Base58 (Bitcoin alphabet) or decode a Base58 string back to text.
| Parameter | Type | Required | Description |
|---|
| text | string | Yes | Text (or Base58 string) to convert. |
| mode | string | No | encode | decode. Default: encode. |
Request
curl -X POST https://toolsonduty.com/api/v1/security/base58 \
-H "Authorization: ******" \
-H "Content-Type: application/json" \
-d '{"text":"hello"}'
Response
{
"ok": true,
"data": {
"result": "Cn8eVZg"
}
}
POST/v1/security/identify-hash1 credit / call
Hash identifier
Guess the algorithm(s) a hash string could be, based on its length and format.
| Parameter | Type | Required | Description |
|---|
| hash | string | Yes | The hash string to identify. |
Request
curl -X POST https://toolsonduty.com/api/v1/security/identify-hash \
-H "Authorization: ******" \
-H "Content-Type: application/json" \
-d '{"hash":"5d41402abc4b2a76b9719d911017c592"}'
Response
{
"ok": true,
"data": {
"guesses": [
{
"type": "MD5 or NTLM",
"note": "32 hex characters"
}
]
}
}
POST/v1/security/totp1 credit / call
TOTP code generator
Generate the current RFC 6238 TOTP code for a Base32 secret (as used by authenticator apps).
| Parameter | Type | Required | Description |
|---|
| secret | string | Yes | Base32 secret key. |
| digits | number | No | Code length. Default: 6. |
| period | number | No | Code validity period in seconds. Default: 30. |
Request
curl -X POST https://toolsonduty.com/api/v1/security/totp \
-H "Authorization: ******" \
-H "Content-Type: application/json" \
-d '{"secret":"JBSWY3DPEHPK3PXP"}'
Response
{
"ok": true,
"data": {
"code": "123456",
"secondsRemaining": 17
}
}
POST/v1/security/ascii851 credit / call
Ascii85 encode / decode
Encode text to Ascii85 (Base85) or decode an Ascii85 string back to text.
| Parameter | Type | Required | Description |
|---|
| text | string | Yes | Text (or Ascii85 string) to convert. |
| mode | string | No | encode | decode. Default: encode. |
Request
curl -X POST https://toolsonduty.com/api/v1/security/ascii85 \
-H "Authorization: ******" \
-H "Content-Type: application/json" \
-d '{"text":"hello"}'
Response
{
"ok": true,
"data": {
"result": "BOu!rDZ"
}
}
POST/v1/security/base64url1 credit / call
Base64URL encode / decode
Encode text to URL-safe Base64 (no padding, - and _ instead of + and /), or decode it back.
| Parameter | Type | Required | Description |
|---|
| text | string | Yes | Text (or Base64URL string) to convert. |
| mode | string | No | encode | decode. Default: encode. |
Request
curl -X POST https://toolsonduty.com/api/v1/security/base64url \
-H "Authorization: ******" \
-H "Content-Type: application/json" \
-d '{"text":"hello"}'
Response
{
"ok": true,
"data": {
"result": "aGVsbG8"
}
}
POST/v1/security/aes-key1 credit / call
AES key generator
Generate a cryptographically random AES key (128, 192 or 256 bits), returned as hex and Base64.
| Parameter | Type | Required | Description |
|---|
| bits | number | No | 128 | 192 | 256. Default: 256. |
Request
curl -X POST https://toolsonduty.com/api/v1/security/aes-key \
-H "Authorization: ******" \
-H "Content-Type: application/json" \
-d '{"bits":256}'
Response
{
"ok": true,
"data": {
"hex": "a1b2...",
"base64": "obL..."
}
}
POST/v1/security/random-bytes1 credit / call
Random bytes generator
Generate cryptographically random bytes, formatted as hex, Base64 or decimal.
| Parameter | Type | Required | Description |
|---|
| count | number | No | Number of bytes (1-1024). Default: 32. |
| format | string | No | hex | base64 | decimal. Default: hex. |
Request
curl -X POST https://toolsonduty.com/api/v1/security/random-bytes \
-H "Authorization: ******" \
-H "Content-Type: application/json" \
-d '{"count":16,"format":"hex"}'
Response
{
"ok": true,
"data": {
"result": "9f2c..."
}
}
POST/v1/security/uuid-v51 credit / call
UUID v5 generator
Generate a deterministic, name-based UUID v5 (SHA-1) from a namespace and name.
| Parameter | Type | Required | Description |
|---|
| name | string | Yes | The name to hash. |
| namespace | string | No | A namespace UUID, or one of dns | url | oid | x500. Default: dns. |
Request
curl -X POST https://toolsonduty.com/api/v1/security/uuid-v5 \
-H "Authorization: ******" \
-H "Content-Type: application/json" \
-d '{"name":"example.com","namespace":"dns"}'
Response
{
"ok": true,
"data": {
"uuid": "cfbff0d1-9375-5685-968c-48ce8b15ae17"
}
}
POST/v1/security/jwt-verify1 credit / call
JWT signature verifier
Verify an HMAC-signed JWT (HS256/384/512) against a secret, and report expiry.
| Parameter | Type | Required | Description |
|---|
| token | string | Yes | The JWT to verify. |
| secret | string | Yes | The HMAC secret key. |
Request
curl -X POST https://toolsonduty.com/api/v1/security/jwt-verify \
-H "Authorization: ******" \
-H "Content-Type: application/json" \
-d '{"token":"eyJhbGciOi...","secret":"my-secret"}'
Response
{
"ok": true,
"data": {
"signatureValid": true,
"expired": false
}
}
POST/v1/security/aes2 credits / call
AES-256-GCM encrypt / decrypt
Encrypt text with a password using AES-256-GCM (output is Base64 of salt+IV+ciphertext), or decrypt it back.
| Parameter | Type | Required | Description |
|---|
| text | string | Yes | mode=encrypt: plain text. mode=decrypt: Base64 payload from this endpoint. |
| password | string | Yes | Password used to derive the encryption key. |
| mode | string | No | encrypt | decrypt. Default: encrypt. |
Request
curl -X POST https://toolsonduty.com/api/v1/security/aes \
-H "Authorization: ******" \
-H "Content-Type: application/json" \
-d '{"text":"secret message","password":"hunter2","mode":"encrypt"}'
Response
{
"ok": true,
"data": {
"result": "base64..."
}
}
POST/v1/security/hmac1 credit / call
HMAC generator
Compute an HMAC of a message with a secret key, returned as hex.
| Parameter | Type | Required | Description |
|---|
| message | string | Yes | Message to sign. |
| secret | string | Yes | Secret key. |
| algo | string | No | SHA-1 | SHA-256 | SHA-384 | SHA-512. Default: SHA-256. |
Request
curl -X POST https://toolsonduty.com/api/v1/security/hmac \
-H "Authorization: ******" \
-H "Content-Type: application/json" \
-d '{"message":"hello","secret":"key"}'
Response
{
"ok": true,
"data": {
"result": "9307b3..."
}
}
POST/v1/security/base321 credit / call
Base32 encode / decode
Encode text to RFC 4648 Base32, or decode Base32 back to text.
| Parameter | Type | Required | Description |
|---|
| text | string | Yes | Text (or Base32 string) to convert. |
| mode | string | No | encode | decode. Default: encode. |
Request
curl -X POST https://toolsonduty.com/api/v1/security/base32 \
-H "Authorization: ******" \
-H "Content-Type: application/json" \
-d '{"text":"hello"}'
Response
{
"ok": true,
"data": {
"result": "NBSWY3DP"
}
}
POST/v1/security/password-strength1 credit / call
Password strength estimator
Estimate a password's entropy, strength rating and rough crack time from its length and character variety.
| Parameter | Type | Required | Description |
|---|
| password | string | Yes | Password to evaluate. |
Request
curl -X POST https://toolsonduty.com/api/v1/security/password-strength \
-H "Authorization: ******" \
-H "Content-Type: application/json" \
-d '{"password":"correcthorsebatterystaple"}'
Response
{
"ok": true,
"data": {
"rating": "Strong",
"entropyBits": 95
}
}
POST/v1/security/shamir-split2 credits / call
Shamir's Secret Sharing - split
Split a secret into N hex shares, where any threshold of them can rebuild it (GF(256) Shamir's Secret Sharing).
| Parameter | Type | Required | Description |
|---|
| secret | string | Yes | The secret to split. |
| shares | number | Yes | Total number of shares to create (2-255). |
| threshold | number | Yes | Minimum shares needed to rebuild (2 to shares). |
Request
curl -X POST https://toolsonduty.com/api/v1/security/shamir-split \
-H "Authorization: ******" \
-H "Content-Type: application/json" \
-d '{"secret":"launch codes","shares":5,"threshold":3}'
Response
{
"ok": true,
"data": {
"shares": [
"01a1b2...",
"02c3d4..."
]
}
}
POST/v1/security/shamir-combine2 credits / call
Shamir's Secret Sharing - combine
Rebuild a secret from at least `threshold` of its Shamir's Secret Sharing hex shares.
| Parameter | Type | Required | Description |
|---|
| shares | string | Yes | Array of hex share strings from security/shamir-split. |
Request
curl -X POST https://toolsonduty.com/api/v1/security/shamir-combine \
-H "Authorization: ******" \
-H "Content-Type: application/json" \
-d '{"shares":["01a1b2...","02c3d4...","03e5f6..."]}'
Response
{
"ok": true,
"data": {
"secret": "launch codes"
}
}
POST/v1/security/csr-parse1 credit / call
CSR parser
Inspect PEM PKCS#10 certificate-signing-request DER metadata without using a remote service.
| Parameter | Type | Required | Description |
|---|
| pem | string | Yes | PEM encoded certificate signing request. |
Request
curl -X POST https://toolsonduty.com/api/v1/security/csr-parse \
-H "Authorization: ******" \
-H "Content-Type: application/json" \
-d '{"pem":"-----BEGIN CERTIFICATE REQUEST-----\\n...\\n-----END CERTIFICATE REQUEST-----"}'
Response
{
"ok": true,
"data": {
"validDer": true,
"publicKeyAlgorithm": "RSA"
}
}
POST/v1/hash/murmur31 credit / call
MurmurHash3 generator
Generate a deterministic 32-bit MurmurHash3 hexadecimal value.
| Parameter | Type | Required | Description |
|---|
| text | string | Yes | UTF-8 text. |
| seed | number | No | Unsigned 32-bit seed. Default: 0. |
Request
curl -X POST https://toolsonduty.com/api/v1/hash/murmur3 \
-H "Authorization: ******" \
-H "Content-Type: application/json" \
-d '{"text":"ToolsOnDuty","seed":0}'
Response
{
"ok": true,
"data": {
"hash32": "00000000"
}
}
POST/v1/security/dane-validate1 credit / call
DANE TLSA record validator
Parse and validate the syntax and numeric ranges of a TLSA record value; no DNS lookup is performed.
| Parameter | Type | Required | Description |
|---|
| record | string | Yes | TLSA value: usage selector matching-type data. |
Request
curl -X POST https://toolsonduty.com/api/v1/security/dane-validate \
-H "Authorization: ******" \
-H "Content-Type: application/json" \
-d '{"record":"3 1 1 aabbccdd"}'
Response
{
"ok": true,
"data": {
"valid": true,
"usage": 3
}
}