6 Free Browser Tools for Everyday Dev Work, and the Gotchas They Catch
Some jobs show up in every project: pretty-printing an API response, reading what is inside a token, writing a cron line, or turning a request into a cURL command. Each one looks trivial until a detail bites you, like a
Some jobs show up in every project: pretty-printing an API response, reading what is inside a token, writing a cron line, or turning a request into a cURL command. Each one looks trivial until a detail bites you, like a 64-bit ID that comes back one digit off or a cron job that runs at a time nobody expected.
The six tools below are from Utilza, a free collection of browser tools. You don't need an account, and each page explains the rules the tool follows. For every tool I've picked the detail that most often goes wrong and shown how the tool deals with it.
- JSON Formatter The JSON Formatter takes minified or messy JSON and indents it with 2 spaces, 4 spaces, or tabs, or squeezes it onto one line. It can sort keys A to Z, and when the input is broken it gives you the line and column of the first error.
The gotcha is big numbers. JavaScript numbers are doubles, so JSON.parse silently rounds any integer above 253:
JSON.parse('{"id": 9007199254740993}').id
// 9007199254740992
The formatter reads JSON with a lossless parser instead, so large integers and decimals such as 1.0 are written back exactly as they came in. Strings are kept byte for byte, Unicode escapes included. Comments and trailing commas are rejected because they aren't valid JSON, and a duplicate key gives a warning and the last value wins. Input is limited to 5 MB.
- JWT Decoder Paste a token into the JWT Decoder and it shows the header and payload, turns exp, iat, and nbf into readable dates with the time left, and verifies the signature. HS256, HS384, and HS512 are checked with a shared secret, and RS, PS, and ES algorithms with a PEM public key, all through the Web Crypto API in your browser.
Many people assume a JWT hides its contents. It doesn't: a signed JWT is Base64URL-encoded JSON, so anyone holding the token can read the payload without a key. The signature only proves who signed it. Even a token that passes verification still has to be checked on your server for exp, aud, and iss.
Two limits are worth knowing. Encrypted tokens (JWE, five parts instead of three) can't be decoded, because their payload needs the private key. JWKS URLs and x5c certificates are not fetched, so you paste the public key yourself.
- Regex Tester The Regex Tester highlights matches as you type and lists every numbered and named capture group with its start and end index. A replace preview shows what replace would return, with $1 and $ references. Flags g, i, m, s, u, and y are supported.
Reordering dates is a good test:
Pattern: (\d{4})-(\d{2})-(\d{2}) flag g
Text: Released 2026-09-26, patched 2026-10-02
Replacement: $3/$2/$1
Result: Released 26/09/2026, patched 02/10/2026
The engine is the one built into your browser, so the syntax is JavaScript's. A pattern copied from PHP or another PCRE flavor can fail here: possessive quantifiers such as a++, atomic groups, recursion, \A, and \Z aren't supported. Watch for catastrophic backtracking too. The tester stops listing after 5,000 matches, but it can't interrupt a single slow match.
- Cron Expression Generator With the Cron Expression Generator you pick how often a job runs and get the five-field line, a plain-English description, and the next five run times. To go the other way and read a line someone else wrote, use the Cron Expression Parser.
Cron has a few traps that this tool makes visible:
*/15 9-17 * * 1-5 runs every 15 minutes on weekdays, and the last run of the day is at 17:45, because the hour field 9-17 covers the whole 17:00 hour.
Intervals restart every hour. With */7 in the minute field the job runs at :56 and then at :00, four minutes later.
A monthly job on the 31st skips the months that don't have one.
Run times are shown in your browser's time zone. The server that runs cron uses its own, often UTC.
The output is standard five-field cron, which Linux crontab, Kubernetes CronJobs, and GitHub Actions read as is. Quartz and Spring add a seconds field, so they need the line adjusted.
- cURL Command Builder The cURL Command Builder turns a URL, method, headers, and body into a command that is quoted correctly for Bash, Windows Command Prompt, or PowerShell. It only writes text and never sends the request, so it works for localhost and internal URLs.
Quoting is where hand-written commands break. Here is the same POST with a Bearer token and a JSON body, first for Bash:
curl 'https://api.example.com/users' \
-H 'Authorization: Bearer TOKEN' \
-H 'Content-Type: application/json' \
--data-raw '{"name":"Ada"}'
and then for Command Prompt, where every double quote inside the body has to be doubled:
curl "https://api.example.com/users" ^
-H "Authorization: Bearer TOKEN" ^
-H "Content-Type: application/json" ^
--data-raw "{""name"":""Ada""}"
The builder sends JSON with --data-raw, so a body that starts with @ isn't read as a file name. It adds -X only when the method isn't implied, since GET is the default and a body implies POST. File uploads with -F aren't built, so add those by hand.
- App Icon Generator If you ship mobile apps, the App Icon Generator takes one square image, ideally 1024 × 1024, and returns a ZIP with every icon size. Apple icons go into AppIcon.appiconset folders with a Contents.json that Xcode reads directly. Android gets mipmap-mdpi to mipmap-xxxhdpi folders with the launcher, round, and adaptive icons, plus the 512 px Play Store icon. The resizing happens in your browser.
It handles two rules that are easy to miss:
App Store Connect rejects an app icon with an alpha channel. Transparent pixels in the iPhone, iPad, and watch icons are filled with a background color you choose, while the Android and macOS files keep their transparency.
An Android adaptive icon is a 108 dp layer, and only the middle 72 dp is sure to show after the launcher applies its mask. The default Safe zone mode shrinks a logo to fit inside it.
The image has to be square. Anything smaller than 1024 px gets a warning, because the larger icons would be enlarged and look soft.
Where to find them
All six run in the browser, and each page lists its limitations next to the tool. The rest of the collection is on the Developer Tools page, along with formatters, validators, and generators for SQL, YAML, UUIDs, and hashes.
Originally published by Dev.to WebDev. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.