Web Crypto Lab - Free Online Cryptography Playground | IconVault
Experiment with SHA-256 hashing, HMAC, AES-GCM encryption, RSA signing and secure random values in an interactive lab. Free, runs fully in your browser.
Web Crypto Lab
Interactive SHA-256, HMAC, AES-GCM and RSA playground
Hash
A hash is a one-way fingerprint: the same input always gives the same output, but you cannot reverse it. Used for file integrity checks, password storage (with a salt and a slow KDF) and content addressing. SHA-1 is shown only for legacy comparison, never use it for security.
HMAC
HMAC proves a message is authentic and untampered: only someone holding the secret key can produce the tag. This is how API webhooks (Stripe, GitHub) prove the payload really came from them. Both sides must share the key.
AES-GCM encrypt / decrypt
AES-GCM is authenticated encryption: it scrambles data so only the password holder can read it, and detects tampering on decrypt. Your password is stretched with PBKDF2 (100,000 rounds) and every encryption uses a fresh random salt and IV.
RSA sign / verify
RSA signing proves authorship: sign with the private key, anyone verifies with the public key. This is how software updates and certificates prove they are genuine. Keys are generated in your browser and never leave it.
Random values
crypto.getRandomValues is the browser's cryptographically secure random generator, suitable for tokens, salts and nonces. Math.random is not: it is predictable and must never be used for security.
Everything on this page uses the Web Crypto API built into your browser, the same primitives real apps use. Keys and passwords never leave this tab. This page is for learning: for production password storage use a dedicated KDF like Argon2 or bcrypt on a server.
About this tool
IconVault's Web Crypto Lab is an interactive cryptography explorer that lets you try the Web Crypto API's core primitives hands-on: SHA-256 hashing, HMAC message authentication, AES-GCM encryption and decryption, RSA signing and verification, and cryptographically secure random values. Every section pairs a live working demo with a plain-English note explaining what the primitive is actually for, so you learn by doing instead of reading specs.
Everything runs through your browser's Web Crypto API, so keys, plaintext and signatures never leave your device and nothing is uploaded. It is free with no signup. Honest note: this is a learning and experimentation lab, not a hardened security product. For production systems, use audited libraries and reviewed key-management practices rather than copy-pasting demo code.
Frequently asked questions
Popular searches
More tools
AES Encryptor
AES-256-GCM text encryption in your browser
HMAC Generator
HMAC-SHA signatures in hex or Base64, with tag verify mode
Header Analyzer
Paste raw response headers, get a security audit in seconds
JWT Builder
Sign and verify HS256/HS384/HS512 tokens
Coming soon
CLI
Coming soon
Figma plugin
Coming soon
VS Code extension
Coming soon
Chrome extension
Coming soon
AI icon generator
Coming soon
Team workspaces
Coming soon