Skip to content
ToolsOnDuty - free online tools
ToolsOnDuty / docs
Browse documentation

Reference / Security & Cryptography

Security & Cryptography API

20 endpoints for security & cryptography workflows. Every call requires bearer authentication and uses the standard ToolsOnDuty response envelope.

Try it

Runs a real request from your browser to your own ToolsOnDuty account. Your key is only kept in this page and is never stored.

POST/v1/hash1 credit / call

Hash generator

Compute MD5, SHA-1, SHA-224/256/384/512 and SHA3-256/512 digests of the given text.

ParameterTypeRequiredDescription
textstringYesText to hash.

Request

curl -X POST https://toolsonduty.com/api/v1/hash \
  -H "Authorization: ******" \
  -H "Content-Type: application/json" \
  -d '{"text":"hello"}'

Response

{
  "ok": true,
  "data": {
    "sha256": "2cf24dba5fb0a30e26e83b2ac5b9e29e1b161e5c1fa7425e73043362938b9824"
  }
}
POST/v1/password1 credit / call

Random password generator

Generate a random password from the selected character sets.

ParameterTypeRequiredDescription
lengthnumberNoPassword length (1-128). Default: 16.
lowerbooleanNoInclude lowercase letters. Default: true.
upperbooleanNoInclude uppercase letters. Default: true.
numbersbooleanNoInclude digits. Default: true.
symbolsbooleanNoInclude symbols. Default: true.
noAmbiguousbooleanNoExclude look-alike characters (O/0, l/1, ...). Default: false.

Request

curl -X POST https://toolsonduty.com/api/v1/password \
  -H "Authorization: ******" \
  -H "Content-Type: application/json" \
  -d '{"length":20}'

Response

{
  "ok": true,
  "data": {
    "password": "kP9#mZ2qT7vR...",
    "entropyBits": 130
  }
}
POST/v1/security/base581 credit / call

Base58 encode / decode

Encode text to Base58 (Bitcoin alphabet) or decode a Base58 string back to text.

ParameterTypeRequiredDescription
textstringYesText (or Base58 string) to convert.
modestringNoencode | decode. Default: encode.

Request

curl -X POST https://toolsonduty.com/api/v1/security/base58 \
  -H "Authorization: ******" \
  -H "Content-Type: application/json" \
  -d '{"text":"hello"}'

Response

{
  "ok": true,
  "data": {
    "result": "Cn8eVZg"
  }
}
POST/v1/security/identify-hash1 credit / call

Hash identifier

Guess the algorithm(s) a hash string could be, based on its length and format.

ParameterTypeRequiredDescription
hashstringYesThe hash string to identify.

Request

curl -X POST https://toolsonduty.com/api/v1/security/identify-hash \
  -H "Authorization: ******" \
  -H "Content-Type: application/json" \
  -d '{"hash":"5d41402abc4b2a76b9719d911017c592"}'

Response

{
  "ok": true,
  "data": {
    "guesses": [
      {
        "type": "MD5 or NTLM",
        "note": "32 hex characters"
      }
    ]
  }
}
POST/v1/security/totp1 credit / call

TOTP code generator

Generate the current RFC 6238 TOTP code for a Base32 secret (as used by authenticator apps).

ParameterTypeRequiredDescription
secretstringYesBase32 secret key.
digitsnumberNoCode length. Default: 6.
periodnumberNoCode validity period in seconds. Default: 30.

Request

curl -X POST https://toolsonduty.com/api/v1/security/totp \
  -H "Authorization: ******" \
  -H "Content-Type: application/json" \
  -d '{"secret":"JBSWY3DPEHPK3PXP"}'

Response

{
  "ok": true,
  "data": {
    "code": "123456",
    "secondsRemaining": 17
  }
}
POST/v1/security/ascii851 credit / call

Ascii85 encode / decode

Encode text to Ascii85 (Base85) or decode an Ascii85 string back to text.

ParameterTypeRequiredDescription
textstringYesText (or Ascii85 string) to convert.
modestringNoencode | decode. Default: encode.

Request

curl -X POST https://toolsonduty.com/api/v1/security/ascii85 \
  -H "Authorization: ******" \
  -H "Content-Type: application/json" \
  -d '{"text":"hello"}'

Response

{
  "ok": true,
  "data": {
    "result": "BOu!rDZ"
  }
}
POST/v1/security/base64url1 credit / call

Base64URL encode / decode

Encode text to URL-safe Base64 (no padding, - and _ instead of + and /), or decode it back.

ParameterTypeRequiredDescription
textstringYesText (or Base64URL string) to convert.
modestringNoencode | decode. Default: encode.

Request

curl -X POST https://toolsonduty.com/api/v1/security/base64url \
  -H "Authorization: ******" \
  -H "Content-Type: application/json" \
  -d '{"text":"hello"}'

Response

{
  "ok": true,
  "data": {
    "result": "aGVsbG8"
  }
}
POST/v1/security/aes-key1 credit / call

AES key generator

Generate a cryptographically random AES key (128, 192 or 256 bits), returned as hex and Base64.

ParameterTypeRequiredDescription
bitsnumberNo128 | 192 | 256. Default: 256.

Request

curl -X POST https://toolsonduty.com/api/v1/security/aes-key \
  -H "Authorization: ******" \
  -H "Content-Type: application/json" \
  -d '{"bits":256}'

Response

{
  "ok": true,
  "data": {
    "hex": "a1b2...",
    "base64": "obL..."
  }
}
POST/v1/security/random-bytes1 credit / call

Random bytes generator

Generate cryptographically random bytes, formatted as hex, Base64 or decimal.

ParameterTypeRequiredDescription
countnumberNoNumber of bytes (1-1024). Default: 32.
formatstringNohex | base64 | decimal. Default: hex.

Request

curl -X POST https://toolsonduty.com/api/v1/security/random-bytes \
  -H "Authorization: ******" \
  -H "Content-Type: application/json" \
  -d '{"count":16,"format":"hex"}'

Response

{
  "ok": true,
  "data": {
    "result": "9f2c..."
  }
}
POST/v1/security/uuid-v51 credit / call

UUID v5 generator

Generate a deterministic, name-based UUID v5 (SHA-1) from a namespace and name.

ParameterTypeRequiredDescription
namestringYesThe name to hash.
namespacestringNoA namespace UUID, or one of dns | url | oid | x500. Default: dns.

Request

curl -X POST https://toolsonduty.com/api/v1/security/uuid-v5 \
  -H "Authorization: ******" \
  -H "Content-Type: application/json" \
  -d '{"name":"example.com","namespace":"dns"}'

Response

{
  "ok": true,
  "data": {
    "uuid": "cfbff0d1-9375-5685-968c-48ce8b15ae17"
  }
}
POST/v1/security/jwt-verify1 credit / call

JWT signature verifier

Verify an HMAC-signed JWT (HS256/384/512) against a secret, and report expiry.

ParameterTypeRequiredDescription
tokenstringYesThe JWT to verify.
secretstringYesThe HMAC secret key.

Request

curl -X POST https://toolsonduty.com/api/v1/security/jwt-verify \
  -H "Authorization: ******" \
  -H "Content-Type: application/json" \
  -d '{"token":"eyJhbGciOi...","secret":"my-secret"}'

Response

{
  "ok": true,
  "data": {
    "signatureValid": true,
    "expired": false
  }
}
POST/v1/security/aes2 credits / call

AES-256-GCM encrypt / decrypt

Encrypt text with a password using AES-256-GCM (output is Base64 of salt+IV+ciphertext), or decrypt it back.

ParameterTypeRequiredDescription
textstringYesmode=encrypt: plain text. mode=decrypt: Base64 payload from this endpoint.
passwordstringYesPassword used to derive the encryption key.
modestringNoencrypt | decrypt. Default: encrypt.

Request

curl -X POST https://toolsonduty.com/api/v1/security/aes \
  -H "Authorization: ******" \
  -H "Content-Type: application/json" \
  -d '{"text":"secret message","password":"hunter2","mode":"encrypt"}'

Response

{
  "ok": true,
  "data": {
    "result": "base64..."
  }
}
POST/v1/security/hmac1 credit / call

HMAC generator

Compute an HMAC of a message with a secret key, returned as hex.

ParameterTypeRequiredDescription
messagestringYesMessage to sign.
secretstringYesSecret key.
algostringNoSHA-1 | SHA-256 | SHA-384 | SHA-512. Default: SHA-256.

Request

curl -X POST https://toolsonduty.com/api/v1/security/hmac \
  -H "Authorization: ******" \
  -H "Content-Type: application/json" \
  -d '{"message":"hello","secret":"key"}'

Response

{
  "ok": true,
  "data": {
    "result": "9307b3..."
  }
}
POST/v1/security/base321 credit / call

Base32 encode / decode

Encode text to RFC 4648 Base32, or decode Base32 back to text.

ParameterTypeRequiredDescription
textstringYesText (or Base32 string) to convert.
modestringNoencode | decode. Default: encode.

Request

curl -X POST https://toolsonduty.com/api/v1/security/base32 \
  -H "Authorization: ******" \
  -H "Content-Type: application/json" \
  -d '{"text":"hello"}'

Response

{
  "ok": true,
  "data": {
    "result": "NBSWY3DP"
  }
}
POST/v1/security/password-strength1 credit / call

Password strength estimator

Estimate a password's entropy, strength rating and rough crack time from its length and character variety.

ParameterTypeRequiredDescription
passwordstringYesPassword to evaluate.

Request

curl -X POST https://toolsonduty.com/api/v1/security/password-strength \
  -H "Authorization: ******" \
  -H "Content-Type: application/json" \
  -d '{"password":"correcthorsebatterystaple"}'

Response

{
  "ok": true,
  "data": {
    "rating": "Strong",
    "entropyBits": 95
  }
}
POST/v1/security/shamir-split2 credits / call

Shamir's Secret Sharing - split

Split a secret into N hex shares, where any threshold of them can rebuild it (GF(256) Shamir's Secret Sharing).

ParameterTypeRequiredDescription
secretstringYesThe secret to split.
sharesnumberYesTotal number of shares to create (2-255).
thresholdnumberYesMinimum shares needed to rebuild (2 to shares).

Request

curl -X POST https://toolsonduty.com/api/v1/security/shamir-split \
  -H "Authorization: ******" \
  -H "Content-Type: application/json" \
  -d '{"secret":"launch codes","shares":5,"threshold":3}'

Response

{
  "ok": true,
  "data": {
    "shares": [
      "01a1b2...",
      "02c3d4..."
    ]
  }
}
POST/v1/security/shamir-combine2 credits / call

Shamir's Secret Sharing - combine

Rebuild a secret from at least `threshold` of its Shamir's Secret Sharing hex shares.

ParameterTypeRequiredDescription
sharesstringYesArray of hex share strings from security/shamir-split.

Request

curl -X POST https://toolsonduty.com/api/v1/security/shamir-combine \
  -H "Authorization: ******" \
  -H "Content-Type: application/json" \
  -d '{"shares":["01a1b2...","02c3d4...","03e5f6..."]}'

Response

{
  "ok": true,
  "data": {
    "secret": "launch codes"
  }
}
POST/v1/security/csr-parse1 credit / call

CSR parser

Inspect PEM PKCS#10 certificate-signing-request DER metadata without using a remote service.

ParameterTypeRequiredDescription
pemstringYesPEM encoded certificate signing request.

Request

curl -X POST https://toolsonduty.com/api/v1/security/csr-parse \
  -H "Authorization: ******" \
  -H "Content-Type: application/json" \
  -d '{"pem":"-----BEGIN CERTIFICATE REQUEST-----\\n...\\n-----END CERTIFICATE REQUEST-----"}'

Response

{
  "ok": true,
  "data": {
    "validDer": true,
    "publicKeyAlgorithm": "RSA"
  }
}
POST/v1/hash/murmur31 credit / call

MurmurHash3 generator

Generate a deterministic 32-bit MurmurHash3 hexadecimal value.

ParameterTypeRequiredDescription
textstringYesUTF-8 text.
seednumberNoUnsigned 32-bit seed. Default: 0.

Request

curl -X POST https://toolsonduty.com/api/v1/hash/murmur3 \
  -H "Authorization: ******" \
  -H "Content-Type: application/json" \
  -d '{"text":"ToolsOnDuty","seed":0}'

Response

{
  "ok": true,
  "data": {
    "hash32": "00000000"
  }
}
POST/v1/security/dane-validate1 credit / call

DANE TLSA record validator

Parse and validate the syntax and numeric ranges of a TLSA record value; no DNS lookup is performed.

ParameterTypeRequiredDescription
recordstringYesTLSA value: usage selector matching-type data.

Request

curl -X POST https://toolsonduty.com/api/v1/security/dane-validate \
  -H "Authorization: ******" \
  -H "Content-Type: application/json" \
  -d '{"record":"3 1 1 aabbccdd"}'

Response

{
  "ok": true,
  "data": {
    "valid": true,
    "usage": 3
  }
}