I built dev tools that literally cannot send your data anywhere
I find myself Googling then subsequently pasting things into random online JSON formatters and JWT decoders which seemed fine at first, but I realized that I have no real way of trusting these sites. Granted I'm not putt
I find myself Googling then subsequently pasting things into random online JSON formatters and JWT decoders which seemed fine at first, but I realized that I have no real way of trusting these sites. Granted I'm not putting in any PII or company proprietary info into them, but still... maybe they're fine. Maybe they're logging every payload to a database somewhere. There's no way to tell from the outside.
After hearing about Chrome extension issues with JSON formatters earlier this year, I stopped assuming it was a paranoid thing to worry about.
So I built Vaultools, a small set of developer micro-tools where every tool page shows a live "network requests sent: 0" counter the whole time you're using it. It's simply a number, updating in real time, that you can watch stay at zero while you paste in something.
Here's a screenshot of where the "network requests sent" counter is:
Here's an automated test showcasing the JSON Formatter tool on the site:

What's actually in it right now
- JSON formatter, with a batch mode to format/validate many blobs at once
- JWT decoder, inspects header/payload claims without a token ever leaving your machine
- UUID / hash generator, for UUIDs and hashing arbitrary text (SHA-256, etc.)
- Regex tester, test and batch-replace against many lines at once
- Timestamp converter, Unix to ISO 8601 and back, batch mode included
Still working on a Base64/URL encoder and a text diff checker, so I guess expect that soon-ish, but I ain't making any promises in this post ahah.
There's also a CLI now, npx vaultools, for anyone who'd rather not open a browser tab at all:
npx vaultools json format package.json
It wraps the exact same tested lib functions as the web pages, so it's the same guarantee. It's meant for CI and scripting
use (looking at you CLI savvy users out there). Piping many files or values through at once is a Pro feature there too, mirroring the site's batch mode.
How it actually works
Every tool page is a static Astro page with zero
server-side logic. The parsing, formatting, and hashing all runs in a small, pure, framework-free TypeScript module that's unit-tested with Vitest and has no fetch, no DOM access, nothing that could phone home even by accident.
Pop open your browser's network tab right now on any tool page and watch it: paste something in, and nothing goes out. The CLI imports those same modules directly, so it's effectively the same but obviously more script-able, not a separate reimplementation.
Full disclosure: a lot of this was built with AI assistance. That's exactly why the tests and the "watch the network tab yourself" pitch matter more here than a "trust me bro" would. You don't have to take my word for the code quality either. Check the behavior directly.
The only server-side code in the whole project is two small Cloudflare Pages Functions, and they only handle the optional Pro tier's payment flow (i.e., Stripe Checkout plus license verification). The tool pages themselves never touch them.
Free vs. Pro
Everything above is free, no account, no signup required. There's an
optional Pro tier ($5/mo or $49 one-time) that adds batch processing across most tools and removes the single small ad slot (I'm still working/thinking about other features too). But the core promise,
nothing you paste ever leaves your browser, applies identically whether or not you pay for anything.
Maybe I should've made this a "buy me a coffee" link or something -- I don't know; I'm still new at this, but I'm still excited to see where I take it!
Try it
Feedback, bug reports, tool requests are all welcome. There's a contact form, or just reply here.
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.