Free. In your browser. Nothing uploaded.

Paste it. Decode it. See what it really does.

Obfuscated JavaScript, a token you don't trust, a base64 blob in a config file, a header from a phishing mail. ghostkit works out what it is and runs the right tool, locally, on your machine.

Run it here

The tools you reach for first.

All 39 tools →

Inspect & analyze

14 tools

Plus 19 more for formatting, hashing, keys and Web3 calldata. Every tool runs in your browser. Three of them (DNS lookup, CSR decoder, SSH key analyzer) call our server because the browser cannot do that work, and the page says so where it applies.

Most looked up: DecodePHP full list →

Know what you're looking at

The technique behind the tool.

All techniques →
No account.
No upload.

The thing you're decoding is usually the thing you least want to send to a stranger's server. So the toolkit doesn't. Decoders, the deobfuscator, the header analyzers, hashing, certificate parsing: all of it is plain JavaScript running in the tab you have open. Turn off wifi and it still works.

The directory is the other half. We don't pretend the browser handles everything. When it doesn't, the provider pages tell you which external tool does, what it costs, and where its limits are.

Start with the paste box at the top. That's the whole idea.

Comparing (/4):

Tool Comparison

Feature
Type
Pricing
Platforms
Description