What the dev tools page does Each panel is its own page — /data/devtools/encode, /data/devtools/hash, /data/devtools/json, /data/devtools/regex — and the tab row switches between them. Keypad arithmetic stays with the standard calculator ; bitwise maths with the programmer calculator .
How to use the panels 01 Encoding. Paste text and pick one of 31 operations across Base64, URL / HTML, radix / Unicode, ciphers / case and escaping. A detection chip guesses JSON, Base64, Base64URL, hex, binary, URL percent-encoding, HTML entities, Unicode escapes, Morse or JWT; the arrows button chains the output back into the input, and the stats bar counts characters, code points, UTF-8 bytes, words, lines, CJK and unique characters. 02 More encoding tools. Code points opens a table of the first 128 characters with code point, UTF-8 bytes, UTF-16 units, entity and Unicode block; Caesar shift runs −25 to 25; escaping produces JSON, CSV, regex, shell and SQL literals. 03 Hashing. Type text or choose a file for all six digests; paste a checksum into the compare box and the matching row turns green, ignoring case and spaces. HMAC takes a key, a message and SHA-1, SHA-256, SHA-384 or SHA-512. 04 JSON. A badge marks the document valid or not, with a line:column trail on error. Five tabs: Format (indent, minify, key sort, escape), Path query, TS interface, CSV and Diff. 05 Regex. Enter a pattern, toggle g i m s u y, and matches highlight with a count and elapsed time. The table lists index range and $1…/named groups; the replacement box previews $1,
lt;name> and
amp;; 14 patterns and an 18-row cheat sheet cover the usual cases.
Worked examples Readouts below come from the panels, typed as shown.
Encoding. Base64-encode CalcX dev tools → Q2FsY1ggZGV2IHRvb2xz . Hex-encode é → C3 A9 , decimal bytes 195 169 , binary 11000011 10101001 . URL encode of a b&c=1/2 → a%20b%26c%3D1%2F2 ; URL decode of a+b%26c → a b&c. ROT13 of Attack at dawn → Nggnpx ng qnja .
Hashing. For abc: CRC-32 352441c2 , MD5 900150983cd24fb0d6963f7d28e17f72 , SHA-1 a9993e364706816aba3e25717850c26c9cd0d89d , SHA-256 ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad ; HMAC-SHA-256 of what do ya want for nothing? under key Jefe reads 5bdcc146bf60754e6a042426089575c75a003f089d2739839dec58b964ec3843 .
JSON. The sample scores depth 4 , keys 12 / 9 unique , nodes 17 , arrays 2 / longest 2 , minified 164 bytes . items[*].price returns $.items[0].price = 9.9 and $.items[1].price = 19.9 ; the diff reports 1 added, 1 removed, 3 changed, 7 same .
Regex. (\d{4})-(\d{2})-(\d{2}) with g over on 2026-07-30 and 2027-01-05 finds 2 matches ; replacing with $3/$2/$1 previews on 30/07/2026 and 05/01/2027. The named-group form shows y=2026 m=07 d=30.
How the panels compute CRC-32 is the reflected CRC-32/ISO-HDLC checksum (polynomial 0xEDB88320) used by ZIP and PNG; MD5 follows RFC 1321, and SHA-1, SHA-256, SHA-384, SHA-512 and HMAC come from the browser's WebCrypto implementation. Encoding works on UTF-8 bytes; regex is the JavaScript RegExp engine, with named groups, lookbehind and the s/u/y flags behaving as in a script.
Limits
The regex guard is bounded. Testing stops after 5,000 matches or roughly 1.5 seconds (match limit 5000 reached), but one catastrophic backtrack cannot be interrupted: patterns run on the page thread.
Files are read whole. File hashing loads the entire file into memory before digesting, so very large files can stall or fail. No security or link work. Nothing is encrypted, signed, cracked or generated, and IDN/Punycode is out of scope; SHA and HMAC need a secure context. Use the network tools for DNS, the IP subnet tool for masks, the standard calculator for arithmetic.
Pitfalls
Hex, binary and decimal encode UTF-8 bytes, not code points. é becomes C3 A9 in hex and 195 169 in decimal bytes, while its code point is U+00E9 — two bytes, one character, both shown in the code-point table.
With g off, the tester shows one match and replaces one hit. \d+ over a1 b22 c333 reports 1 match ; the preview becomes a# b22 c333, not a# b# c#.
The JSON diff aligns arrays by index. Inserting 0 at the front of [1,2,3] reports 3 changed and 1 added , not one insertion.
Where it is used Debugging an encoded payload A webhook arrives as a Base64URL blob: paste it, accept the suggested decode, then chain the output back into the input for a second pass.
Checking a download File mode hashes stored bytes, so a .zip or installer can be checked against the publisher's MD5 or SHA-256; the compare box ignores case and spaces, as checksum files print them.
Turning an API response into code Format for a readable indent, sort keys for a stable diff, query items[*].id to see what arrived, then emit TypeScript interfaces before writing the client; the CSV tab moves the document both ways.
Privacy All encoding, hashing, JSON and regex work runs inside your browser; files are read locally and nothing is uploaded, stored or logged.
References
IETF, RFC 4648: The Base16, Base32, and Base64 Data Encodings , rfc-editor.org (访问日期:2026-10-01)— Base64 alphabets and padding.
IETF, RFC 1321: The MD5 Message-Digest Algorithm , rfc-editor.org (访问日期:2026-10-01)— MD5 specification and the abc vector.
NIST, FIPS 180-4: Secure Hash Standard (SHS) , csrc.nist.gov (访问日期:2026-10-01)— SHA-1, SHA-256, SHA-384 and SHA-512.
IETF, RFC 4231: Identifiers and Test Vectors for HMAC-SHA-224/256/384/512 , rfc-editor.org (访问日期:2026-10-01)— the Jefe HMAC-SHA-256 vector.
IETF, RFC 8259: The JavaScript Object Notation (JSON) Data Interchange Format , rfc-editor.org (访问日期:2026-10-01)— JSON grammar and parsing.
Ecma International, ECMA-262: RegExp Objects , tc39.es (访问日期:2026-10-01)— flags, groups and replacement patterns.
Calculators in this hub
Hand-picked tools, one click away. The mini versions compute live and carry your values into the full calculator.
Sources & review
Reviewed by CalcX Editorial Team
Updated 2026-10-01