Skip to content
We use cookies to improve the site and measure traffic. See our Cookie Policy. You can accept or reject non-essential cookies.
  • Free
  • No signup
  • Fast

About the Security Toolkit toolkit

Use the Security Toolkit when you need to harden a site or debug auth — security headers, TLS certificates, cookie flags, JWT decode, password strength and generation, message digests, and SPF/DKIM/DMARC. Open any tool in the browser with no signup. All Phase 1 tools are API-backed via REST and MCP on one API key and 500 free requests per month. Mixed HTTP assets on HTTPS pages stay in the SEO Toolkit (Mixed Content Checker).

Frequently asked questions

What jobs does the Security Toolkit cover?

Web response hardening (headers, TLS, cookies), developer crypto helpers (JWT, passwords, hashes), and email authentication DNS (SPF/DKIM/DMARC). Not antivirus, port scanning, or breach monitoring.

Do I need an account to use Security Toolkit tools?

No for browser use. Create a developer account only if you want REST or MCP access.

How does this relate to the Developer Toolkit?

Headers, TLS, cookies, JWT, password, and hash tools also appear in the Developer Toolkit for builders. Full email-auth DNS (SPF/DKIM/DMARC) lives in the Security Toolkit.
Back to Toolkits

Security Toolkit

HTTP security headers, TLS certificates, cookies, JWTs, passwords, hashes, and email authentication checks.