What it is
Dev Toolbox (app id dev) is a set of small utilities for developers, designers and anyone who handles data: format JSON, encode and decode Base64, URLs and HTML, read a JWT, make UUIDs, hashes, passwords, QR codes and barcodes, convert timestamps, number bases and colors, test regular expressions and make color palettes. It replaces websites such as jsonformatter, base64decode, jwt.io or Coolors, and apps such as DevToys.
Everything runs on the PC, offline: nothing typed or pasted into Dev Toolbox is sent anywhere, and no tool needs a download.
Opening it and what it costs
- On the home screen Dev Toolbox is in the Utilities group. The home search finds it, and each tool, by words like "json", "base64", "uuid", "qr", "barcode" or "palette".
- Inside the app, the list on the left has the groups Data, Make, Check, Color and More (the tools still coming), and a Find box that filters the list.
- Addresses inside Octoolo:
#/app/dev, and#/app/dev/<task id>for one tool (for example#/app/dev/json-format). A shortcut can open it withOctoolo.exe --open=app/dev/<task id>. - Dev Toolbox needs Octoolo Cloud (the subscription) or its free trial. Without it, opening the app shows "Dev Toolbox comes with Octoolo Cloud" with Start your free week and I have a license key (after a subscription has ended: "Your Octoolo Cloud has ended" with Subscribe). Prices, the trial and the three free apps are in Prices and limits.
Tasks
The 16 tools that work in version 0.8.0, in the order the app lists them:
Data
- JSON formatter (
json-format): format, validate and minify JSON. - JSON ↔ CSV (
json-csv): turn a JSON list into CSV and CSV into JSON. - Base64 encode & decode (
base64): text to Base64 and back. - URL encode & decode (
url-encode): percent-encoding for web addresses. - HTML entities (
html-entities): escape and unescape HTML. - JWT decoder (
jwt-decode): read the header and claims of a JSON Web Token.
Make
- UUID generator (
uuid): random version 4 UUIDs, 1 to 1,000 at a time. - Hash generator (
hash): SHA-1, SHA-256, SHA-384 and SHA-512 of a text. - Password generator (
password): strong random passwords. - QR code generator (
qr-code): a QR code for a link or text, as PNG or SVG. - Barcode generator (
barcode): EAN-13, EAN-8, UPC-A, UPC-E, ISBN, ITF-14, Code 128, Code 39, Code 93 and Codabar barcodes, as PNG or SVG. - Timestamp converter (
timestamp): Unix time to a date and back.
Check
- Regex tester (
regex-tester): try a regular expression and see every match. - Number base converter (
number-base): binary, octal, decimal and hexadecimal.
Color
- Color converter (
color-convert): HEX, RGB and HSL, with a preview and contrast ratios. - Color palette generator (
color-palette): colors that go together, from one color, at random, or from a picture.
Not available yet (listed under More with a Soon tag): YAML ↔ JSON (yaml-json), CSS & JS minifier (minify), SQL formatter (sql-format) and Cron explainer (cron). Their pages say "… is on its way." Do not promise a date.
How the text tools work
JSON formatter, JSON ↔ CSV, Base64 encode & decode, URL encode & decode, HTML entities and JWT decoder share one layout: an Input box on the left and a Result box on the right. The result is worked out as you type; there is no Convert button. Copy (it changes to "Copied" for a moment) copies the result; Clear empties the input. When the input cannot be read, a message under the boxes says why.
What is typed is not kept: switching to another tool, leaving Dev Toolbox or closing Octoolo clears it. Nothing is saved to files; copy the result where you need it.
JSON formatter
JSON formatter (json-format) checks and reformats JSON:
- Format: 2 spaces (default), 4 spaces, Tabs or Minify (everything on one line, no spaces).
- Sort keys: sorts every object's keys alphabetically, inside nested objects too (arrays keep their order).
- Numbers too long for normal JavaScript precision (more than 15 digits, such as 64-bit IDs like
12345678901234567890) are kept exactly as written. Other numbers are written the standard way:1.50becomes1.5,1e3becomes1000. - Invalid JSON shows "Not valid JSON: " followed by the reason (for example where the unexpected character is).
It accepts strict JSON only: comments, trailing commas, single quotes and unquoted keys (JSON5, JavaScript objects) are errors. It has no tree view and no JSON path or schema check.
JSON ↔ CSV
JSON ↔ CSV (json-csv) converts between a JSON list and CSV text:
- Direction: JSON → CSV (default) or CSV → JSON.
- Separator: Comma (default), Semicolon or Tab, for both directions.
- JSON → CSV: the input is a JSON array of objects (a single object makes one row). The columns are every key found, in the order first seen. Nested objects and arrays are written into the cell as JSON text;
nullmakes an empty cell; an array of plain values makes one column namedvalue. Cells with quotes, separators or line breaks are put in quotes. Numbers longer than about 15 digits (64-bit IDs) are rounded here (unlike the JSON formatter); put them in quotes in the JSON to keep them exact. - CSV → JSON: the first row is the header (the keys); each following row becomes an object. Values stay text (
"1815", not1815), a missing cell is"", empty lines are skipped, and quoted cells may hold separators and line breaks.
It works on pasted text; to open or save CSV or Excel files, use Converters' Convert spreadsheets (Converters) or the Spreadsheets app (Spreadsheets).
Base64, URL and HTML encoding
- Base64 encode & decode (
base64): Direction Encode or Decode. Text is encoded as UTF-8, so accents and emoji work. URL-safe alphabet uses-and_instead of+and/and leaves out the=padding. Decoding accepts both alphabets, missing padding and line breaks. If the input is not Base64, or decodes to bytes that are not text (a picture, a file), it says "This is not Base64 text, or it does not decode to text." It works on text only: it cannot encode a file or a picture, nor save decoded bytes as a file. - URL encode & decode (
url-encode): Encode escapes everything that is not safe in one part of an address (encodeURIComponent). Keep the address's own characters (: / ? & =) encodes a whole address instead, keeping its structure (encodeURI). Decode turns%sequences (such as%20) back into characters and+into a space; a broken sequence gives "This text has a broken % sequence." - HTML entities (
html-entities): Escape turns&,<,>,"and'into&,<,>,"and'; Also non-ASCII characters also turns every accented letter, emoji and other non-ASCII character into a numeric entity (é). Unescape turns named and numeric entities back into characters.
JWT decoder
JWT decoder (jwt-decode) shows what is inside a JSON Web Token: paste the token (it starts with eyJ) into Input.
- The Result shows
// Headerand// Payloadas formatted JSON, and, when the token has them,// Dates:iat(issued at),nbf(not before) andexp(expires) in the PC's local time, with "(expired)" after anexpthat has passed. - It only decodes. The last line always says "The signature is not checked: that needs the issuer's key." It cannot verify a signature, create or sign tokens, or decrypt encrypted tokens (JWE).
- Messages: "A JWT has three parts separated by dots." (there is no dot in the text), "This token's parts are not Base64 JSON." (the header or the payload is not Base64url-encoded JSON).
- The token stays on the PC: it is decoded in the app and sent nowhere.
UUID generator
UUID generator (uuid) makes random version 4 UUIDs (also called GUIDs) with the PC's secure random generator:
- How many: 1 to 1,000 (5 by default).
- Hyphens (on by default) and Uppercase (off by default).
- Generate makes a new set; changing a setting also makes a new set.
- The list is in the pane "UUIDs (version 4)", one per line, with Copy.
It makes version 4 only: not version 1, 5, 7, nil UUIDs or ULIDs.
Hash generator
Hash generator (hash) shows the SHA-1, SHA-256, SHA-384 and SHA-512 hashes of what is typed in Text ("Type or paste the text to hash"), updated as you type, each with Copy. The text is hashed as UTF-8. Uppercase shows the hex digits in capitals.
- It hashes text only: it cannot hash a file (to check a download's checksum), and it does not make MD5, CRC32, SHA-3, HMAC, bcrypt or other password hashes.
- An empty box shows the hashes of empty text.
- Line breaks count: text pasted with a trailing new line gives a different hash.
Password generator
Password generator (password) makes random passwords with the PC's cryptographic random generator (each character drawn with rejection sampling, so every allowed character is equally likely):
- Length: 4 to 256 characters (20 by default).
- How many: 1 to 100 (5 by default).
- Kinds of characters, each a switch: A–Z, a–z, 0–9 and !@# (the symbols
! @ # $ % ^ & * ( ) - _ = + [ ] { } ; : , . ? / ~). All on by default. - No look-alikes (O 0 l 1) (on by default) leaves out
O,0,o,I,l,1and|. - Generate makes a new set; changing a setting also makes a new set. The list is in the pane Passwords, one per line, with Copy.
- Strength and Entropy: the entropy is length × log2(number of possible characters), in bits. Strength: Excellent from 100 bits, Strong from 75, Fair from 50, Weak below. The default (20 characters, all kinds, no look-alikes) is about 127 bits, Excellent.
- With no kind switched on: "Choose at least one kind of character."
Every character is drawn independently, so a password is not guaranteed to hold one of each kind (rare for long passwords). The passwords are not saved anywhere; Copy puts them on the Windows clipboard like any other copy. To keep passwords, use the Passwords app, which has its own generator (Passwords).
QR code generator
QR code generator (qr-code) makes a QR code from what is typed in Link or text (it starts with https://octoolo.com as an example), drawn live:
- Size: 64 to 2,048 pixels (512 by default), the width and height of the PNG. When the size is too small for a code with a lot of text, the PNG comes out bigger (4 pixels per dot).
- Error correction: Low, Medium (default), High or Max (QR levels L, M, Q, H: about 7%, 15%, 25% and 30% of the code can be damaged or covered and still scan). Higher levels make a denser code.
- Dots and Background: the two colors (dark #0D0D0D on white by default). Dark dots on a light background scan best; some scanners cannot read light dots on a dark background.
- Save PNG saves
qr-code.pngat the chosen size; Save SVG savesqr-code.svg, sharp at any size, for print. - The code has a quiet margin of 2 modules around it.
- With the box empty it says "Type a link or some text." and the Save buttons are greyed out.
How much fits: a QR code holds at most 2,953 bytes of text at Low, 2,331 at Medium, 1,663 at High and 1,273 at Max (fewer for accented letters and emoji, which take 2 to 4 bytes each; more for digits only). Too much text shows "The amount of data is too big to be stored in a QR Code".
The QR code holds the text itself: it does not go through a link service, so it never expires, counts no scans and cannot be changed after it is printed. There are no forms for Wi-Fi, contact cards (vCard), email or SMS codes: type the text in that format yourself (for Wi-Fi: WIFI:T:WPA;S:network name;P:password;;). It cannot put a logo in the middle, and it cannot read (scan) QR codes.
Barcode generator
Barcode generator (barcode) draws barcodes to print:
- Pick the Kind of barcode. Each kind starts with an example number, and a line under it says what it is used for.
- Type into Number or text (ISBN for ISBN). A note under it explains what was added (a check digit, start and stop letters), or a message explains what is wrong; the barcode is drawn live.
- Adjust the look, then Save PNG or Save SVG. Files are named
barcode-<kind>-<number>.png(or.svg), for examplebarcode-ean13-5901234123457.png. The Save buttons are greyed out while there is a message about what is wrong.
The kinds and what they take:
| Kind | Takes | Check digit |
|---|---|---|
| Code 128 | Any plain letters, digits, spaces and symbols (ASCII), up to 80 characters; no accents or emoji. | Built into the code. |
| EAN-13 | 12 digits (the check digit is added) or all 13 (the check digit is checked). Spaces and hyphens are ignored. | GS1. |
| UPC-A | 11 digits, or all 12. | GS1. |
| EAN-8 | 7 digits, or all 8. | GS1. |
| UPC-E | 6 digits (number system 0 and the check digit are added), 7 digits starting with 0 or 1 (the check digit is added), or all 8. | The check digit of the UPC-A number it stands for. |
| ISBN | An ISBN-13 starting with 978 or 979 (12 or 13 digits), or an older ISBN-10 (10 characters, the last may be X), which becomes 978 + its first nine digits + a new check digit. Hyphens, spaces and a leading "ISBN" are fine. Drawn as an EAN-13, with "ISBN …" printed above the bars when the number is shown. | GS1 (ISBN-10's own check is verified first). |
| ITF-14 | 13 digits, or all 14 (shipping cartons). | GS1. |
| Code 39 | A to Z, 0 to 9, spaces and - . $ / + %. Small letters are made capitals. Add a check character adds the optional modulo-43 check. | Optional (mod 43). |
| Code 93 | A to Z, 0 to 9, spaces and - . $ / + % (capitals only: small letters are an error). | Built into the code. |
| Codabar | Digits and - $ : / . +. Start and stop letters A are added; type A, B, C or D at both ends to choose your own. | None. |
The look (all but PNG size apply to both PNG and SVG):
- Bar width: the thinnest bar, 1 to 10 pixels (2 by default).
- Bar height: 10 to 600 pixels (100 by default).
- Text size: 8 to 60 pixels (18 by default).
- Quiet zone: blank space around the bars, 0 to 100 pixels (12 by default).
- Bars and Background colors; See-through makes the background transparent.
- Show the number under the bars (on by default).
- PNG size: PNG 1×, PNG 2× (default) or PNG 4× (print): the PNG is drawn that many times bigger. SVG is sharp at any size.
The app's advice: "Dark bars on a light background scan best. Print at 100% size or larger, and test a printed code with the scanner or phone that will read it."
Messages, by kind (quoted as the app shows them; N is the number of digits):
- "Type what the barcode should hold." (the box is empty)
- "EAN-13 takes digits only." (also UPC-A, EAN-8, ITF-14, UPC-E)
- "EAN-13 has 13 digits: type 12 and the check digit is added, or all 13. This has 9."
- "The last digit should be 7, not 3. It is a check digit worked out from the other 12: type those 12 and it is added for you." (a wrong check digit; for UPC-E: "The last digit should be 5, not 3. It is the check digit of the UPC-A number this code stands for.")
- "A UPC-E code starts with 0 or 1 (its number system)." and "UPC-E has 8 digits: a 0 or 1, six digits and a check digit. Type 6, 7 or 8 digits. This has 5."
- "This ISBN-10 should end in X, not 5. Check the number on the book.", "An ISBN-13 starts with 978 or 979.", "Type an ISBN: 13 digits starting with 978 or 979, or an older 10-character one (hyphens are fine)."
- "Code 128 holds plain letters, digits, spaces and symbols (ASCII), not accents or emoji." and "Keep Code 128 under 80 characters; scanners struggle with longer ones."
- "Code 39 holds A to Z, 0 to 9, spaces and - . $ / + %." / "Code 93 holds A to Z, 0 to 9, spaces and
- . $ / + %, like Code 39."
- "Codabar holds digits and - $ : / . +, with a letter A to D at each end if you want one."
- "This cannot be drawn as EAN-13." (with the kind's name: the value passed the checks but could not be drawn)
It cannot make QR codes (use the QR code generator), Data Matrix, PDF417, Aztec, GS1-128 with application identifiers, or EAN/UPC 2- and 5-digit add-on codes (the price add-on on books). It makes one barcode at a time (no lists or sheets of labels), and it does not issue real product numbers: EAN/UPC numbers for selling in shops come from GS1, ISBNs from the national ISBN agency.
Timestamp converter
Timestamp converter (timestamp):
- Unix time ("Seconds, or milliseconds when longer"): a number of seconds since 1 January 1970 UTC; a number whose whole part has more than 11 digits is read as milliseconds. Negative numbers (before 1970) and decimals work. Now fills in the current time.
- It shows Your time (in the PC's time zone, written out), UTC, ISO 8601 and Relative ("3 days ago", "in 2 hours"), each with Copy.
- Date and time to Unix time: pick a date and time (in the PC's time zone, to the second) and it shows Seconds and Milliseconds.
- A value that is not a number: "That is not a Unix time: type the seconds (or milliseconds) since 1970."
It does not convert between other time zones (the Calculator's Time zone converter does: Calculator), and it does not read date strings typed as text.
Regex tester
Regex tester (regex-tester) tries a JavaScript (ECMAScript) regular expression on a text:
- Pattern: the expression, without slashes (an email-like example is filled in).
- Flags ("g i m s u y"):
iignore case,mmulti-line,sdot matches new lines,uUnicode,ysticky,dindices; other letters cannot be typed. Every match is always found (gis added if it is missing). - Test text: the text to search. Matches shows the count and the text with every match highlighted; when the expression has groups, each match is listed as
#1 $1=… $2=…(∅ for a group that did not take part). - An invalid expression shows the browser's error message (for example "Invalid regular expression: … Unterminated group"); a flag typed twice gives "Invalid flags supplied to RegExp constructor …".
- At most 500 matches are counted and shown. Empty matches are counted but not highlighted.
- The expression runs again on every key press, with no time limit: a pattern that backtracks heavily (such as
(a+)+$) on a long text can make the window stop responding until it finishes.
It uses JavaScript's regex flavor: lookbehind and named groups work; PCRE-only features (possessive quantifiers, recursion, \A, \Z) do not. It has no replace, no explanation of the expression, and no code generation.
Number base converter
Number base converter (number-base) has four boxes, Binary, Octal, Decimal and Hexadecimal; typing in any of them fills the others (it starts with 255).
- Numbers of any size are exact (no rounding, however many digits).
- Each box takes its own prefix (
0bin Binary,0oin Octal,0xin Hexadecimal); spaces and underscores are ignored; hexadecimal letters are shown in capitals. - Whole numbers of 0 or more only: no minus sign, fractions or two's complement. A wrong digit shows "That is not a base-16 number." (with the box's base), and the wrong character is not kept.
Color converter
Color converter (color-convert):
- Color ("#hex, rgb(), hsl() or a name like teal"): a hex color with or without
#(3, 4, 6 or 8 digits, the last two for transparency),rgb()/rgba(),hsl()/hsla()or a CSS color name. Pick opens a color picker. - It shows a swatch and HEX, RGB and HSL (with Copy; with transparency they become 8-digit hex,
rgba()andhsla()), and Contrast on white and Contrast on black as WCAG ratios (4.5 : 1 or more is enough for normal text). - Something it cannot read: "That is not a color this tool knows."
It does not convert to CMYK, Pantone or other print color systems. To pick a color from a picture, use the Photo Editor's Color picker (the Eyedropper: Photo Editor).
Color palette generator
Color palette generator (color-palette) has three ways to Make a palette:
From a color: type a hex color ("#hex, like #2A62F2") or pick one, then choose Colors that:
- Analogous (5 colors): neighbors on the color wheel.
- Complementary (5): the opposite color, with lighter and darker steps.
- Split (5): the two colors beside the opposite one.
- Triadic (5, the default): three colors evenly spaced around the wheel.
- Tetradic (4): four colors in a square on the wheel.
- Monochrome (5): one hue, lighter and darker, more and less vivid.
- Shades and tints (9): steps from almost white to almost black, with the base color in its place, a scale for a design system.
The base color is always one of the colors. A color that is not a hex color shows "Type a color as # and six hex digits, like #2A62F2, or pick one."
Random: New palette (or the Space key, when no box or button has the focus) makes a palette that hangs together: hues from one scheme (close, opposite, three or four apart) and lightness spread from dark to light. Colors: 2 to 10 (5 by default). Lock on a color keeps it on the next palette ("Locked"; the scheme then starts from the first locked color).
From a picture: drop a picture on Drop a picture ("Its main colors become a palette. The picture stays on your PC.") or click Choose a file, and choose Colors (2 to 12, 5 by default). The main colors are found by clustering the picture's pixels (k-means in the CIELAB color space, on a copy at most 200 pixels on its longest side; see-through pixels are left out), biggest first, each with "…% of the picture". The same picture always gives the same palette. Another picture changes it. A file that cannot be opened: "This picture could not be opened. Try a PNG, JPG, WebP or GIF."
Each color card shows its HEX, rgb() and hsl() values with HEX, RGB and HSL copy buttons, and its contrast with white and with near-black (#0D0D0D) text, graded AAA (7 : 1 or more), AA (4.5), AA large (3) or Fails. In Random and From a picture, Build on this color makes harmonies from that color.
Use the palette: Copy HEX list (comma-separated), Copy CSS variables (:root { --color-1: #…; }, also shown below), Copy JSON (hex, rgb and hsl of each color) and Save PNG (palette.png, one tall block per color with its hex code).
Palettes are not saved: copy or save the PNG to keep one. It cannot export Adobe swatch files (ASE), and it has no color-blindness preview.
Options and settings
Dev Toolbox has no settings of its own and keeps no settings between visits: each tool starts with its defaults.
Keyboard shortcuts
| Keys | Does |
|---|---|
| Space | Color palette generator, Random: a new palette (when no box or button has the focus) |
| Ctrl+, | Opens Octoolo's Settings (anywhere in Octoolo) |
The tools otherwise use Windows' usual text keys (Ctrl+A, Ctrl+C, Ctrl+V) in their boxes.
Where it keeps things
Nothing. Dev Toolbox saves no history, inputs or palettes: what is typed lasts while the tool is open. Files are written only when you press Save PNG or Save SVG (QR codes, barcodes, palettes), to the place you choose in Windows' Save dialog.
Downloads it needs
None. Every tool, including the QR code and barcode libraries, is part of Octoolo and works offline.
Privacy
Nothing leaves the PC. JSON, tokens, passwords, hashes and everything else typed or pasted into Dev Toolbox are worked out in the app on the computer; no tool contacts the internet. Octoolo's usage statistics (if left on) note which tools are opened and that a file was saved, never what is typed: see Privacy and data.
Troubleshooting
"Not valid JSON: …"
The JSON formatter (or JSON ↔ CSV) could not read the input. The reason after the colon says where. Common causes: a trailing comma, single quotes instead of double quotes, comments, keys without quotes, or text copied with "smart" quotes. Fix the place named and the result appears as you type. In JSON ↔ CSV, also check the Direction: CSV pasted while JSON → CSV is chosen gives this message; choose CSV → JSON.
"This is not Base64 text, or it does not decode to text."
The input has characters that are not Base64, or it decodes to binary data (a picture, a file) rather than text. Dev Toolbox decodes Base64 text only; it cannot save the bytes as a file.
The JWT decoder says "This token's parts are not Base64 JSON."
The text is not a JSON Web Token (or only part of it was copied). A JWT has three parts separated by dots, and the first two start with eyJ. Copy the whole token, without "Bearer " in front. An encrypted token (JWE, five parts) cannot be read.
The JWT decoder says the signature is not checked
That is by design: "The signature is not checked: that needs the issuer's key." The decoder only shows what is inside a token; it cannot tell whether the token is genuine.
The hash does not match the one on a website
Hash generator hashes the text typed in the box (as UTF-8), not a file. A hash published for a download is the file's hash, which this tool cannot make. For text, check for an extra space or line break, which changes the hash.
The QR code generator says "The amount of data is too big to be stored in a QR Code"
The text is longer than a QR code holds at the chosen error correction (2,953 bytes at Low, 1,273 at Max). The picture is not updated (it keeps the last code that fitted, or stays blank), and Save PNG and Save SVG are greyed out until the text fits. Shorten the text or choose a lower Error correction. For a long link, shorten it first.
A printed QR code or barcode does not scan
Use dark dots or bars on a light background, keep the quiet zone (Quiet zone for barcodes), and print at full size or bigger. For QR codes, choose High or Max error correction and save as SVG for print; for barcodes, PNG 4× (print) or SVG. Test with the scanner or phone that will read it.
The barcode generator says the last digit is wrong
For EAN, UPC, ISBN and ITF-14 the last digit is a check digit worked out from the others. Either the number was typed wrong, or type the number without its last digit and the generator adds the right one.
"Choose at least one kind of character."
In the Password generator every kind of character (A–Z, a–z, 0–9, !@#) is switched off. Switch at least one on.
Limits and what it cannot do
- It cannot convert YAML, minify CSS or JavaScript, format SQL or explain cron schedules yet: these tools (
yaml-json,minify,sql-format,cron) are not available yet. - It cannot open or save files in the text tools (JSON, CSV, Base64): it works on pasted text.
- It cannot hash files, make MD5, CRC32, SHA-3 or any hash other than SHA-1, SHA-256, SHA-384 and SHA-512, or check passwords' bcrypt/argon2 hashes.
- It cannot verify or sign JWTs.
- It cannot read or scan QR codes or barcodes, and makes one code at a time.
- It cannot make Data Matrix, PDF417, Aztec or GS1-128 codes, or EAN/UPC add-on codes.
- It has no XML or TOML formatter, no diff tool (Text Studio's Compare text compares two texts: Text Studio), no Lorem ipsum (in Text Studio) and no API client.
- It keeps nothing between visits.