A production API returned a 500KB JSON error blob at 2 AM, and the on-call engineer pasted it — credentials and all — into a random online formatter. The formatting worked. So did the credential leak, into a stranger's server logs. I have seen this movie too many times: debugging with tools that upload your secrets. This guide is the alternative: format JSON, decode Base64 and JWTs, test regex, hash and mint UUIDs — everything locally, nothing uploaded, secrets stay in your tab.
Here is the promise: you will learn a local-first debugging workflow covering the seven operations developers repeat daily, with exact behaviors (trailing commas, padding, exp skew, bulk UUID counts) and the security boundaries that matter. I ran every example below in October 2026 against real payloads. Work alongside me starting at our free JSON formatter.
Part of the blog guides. Format in JSON formatter; decode in Base64 and JWT decoder; test in regex tester.
The local-first debugging loop (paste → inspect → fix → verify)
- Paste into the local tool, never a cloud box: API replies, tokens, hashes and patterns stay in your browser tab. Close the tab and they are gone — no retention policy to read.
- Let the tool point at line:column: a missing comma at 1:18 beats staring at 10,000 lines. Fix, re-paste, confirm green.
- Decode one layer at a time: JWT → Base64 segments → JSON claims. Each layer gets its own tool and its own verification.
- Verify, don't trust: decoding is not verifying — a decoded signature proves nothing. Expiry, audience and algorithm checks are separate steps below.
Why JSON.parse fails: trailing commas, comments, single quotes
Strict JSON accepts exactly one grammar — JavaScript object literals are not it. The three killers I see weekly:
| Cause | Example | Fix |
|---|---|---|
| Trailing comma | {"a": 1,} | Delete the comma; minifiers flag it |
| Comments | {// note
"a": 1} | Strip comments (JSONC is not JSON) |
| Single quotes | {'a': 1} | Double-quote all keys and strings |
| Duplicate keys | {"a": 1, "a": 2} | Last wins silently — dedupe |
Paste the payload into the JSON formatter — it pinpoints line and column, pretty-prints 500KB replies instantly, and minifies ~20% smaller for transport. Split payloads over 10MB before pasting; oversized dumps hang tabs regardless of tool. Errors guide: JSON.parse error fixes. Tree-view large responses in the JSON tree viewer, and convert configs with the JSON to YAML tool.
Base64 standard vs URL-safe: padding, +/ vs -_
Standard Base64 (A–Z a–z 0–9 + / with = padding) breaks in URLs — + becomes a space, / splits paths. URL-safe mode swaps +/ for -_ and drops padding. Rule: standard for MIME/email/data-URLs, URL-safe for tokens, query params and filenames. Costs to remember: ~33% size overhead, UTF-8 emoji encode as 4 bytes first (café → Y2Fmw6k=), and 76-char mail wrapping is a transport concern, not storage. JWT segments are Base64URL without padding by spec — decode them in the Base64 tool, then inspect claims in the JWT decoder. Modes: URL-safe vs standard.
SHA-256 vs MD5: digest lengths and when legacy is acceptable
hello → SHA-256 2cf24dba… (64 hex chars), MD5 5d41402a… (32). Lengths identify algorithms at a glance: 40 SHA-1, 64 SHA-256, 128 SHA-512. Use SHA-256 for integrity checks and fingerprints; MD5 only for legacy manifest compatibility — never for passwords (use bcrypt/argon2 server-side). Flip one letter (hallo) and the avalanche effect rewrites the whole digest. Compare side by side in the hash generator, step up to keyed HMAC in the HMAC tool, and encrypt (not just hash) secrets with the AES encryptor. Guide: hash comparison.
Seeding test DBs: how many UUIDs without collisions
v4 UUIDs carry 122 random bits — you can mint millions per second for fixtures with effectively zero collision risk (birthday math needs ~2.7 quintillion for 50% odds). Practical flow: generate 10,000 in bulk, bulk-copy into seed scripts, dedupe on insert as belt-and-braces. Prefer UUIDs over auto-increment IDs in test data to avoid order-dependent flakes; prefer random-string only for human-readable codes, never for unguessable tokens. Bulk mint in the UUID generator. Seeding guide: UUID seeding.
Regex flags g/i/m/s and capture groups that actually capture
Two thirds of regex pain is flags, not patterns. g finds all matches (d+ pulls 42 from “Order 42”), i ignores case, m makes ^/$ per-line for 4000-line logs, s lets . cross newlines. Named groups ((?<year>d{4})-(?<month>d{2})) beat numbered ones for 2024-05-01 extraction; non-capturing (?:…) keeps indexes stable. Greedy .* backtracks catastrophically on large inputs — prefer lazy .*? or explicit classes. Our regex tester highlights matches with per-flag control and runs catastrophic patterns in a worker with timeouts instead of freezing your tab. Flags lab: capture groups guide.
JWT expiry without trust: exp, skew and alg:none
Decoding shows claims; verification proves them — do both, in that order. Check exp against now (allow ~30s clock skew, sync NTP), confirm aud is your service and iss your IdP, and reject alg:none unconditionally — unsigned tokens must never authorize. exp: 1717252800 two hours past means expired, full stop, regardless of a valid-looking signature from the wrong key. Paste into the JWT decoder (redact emails before screenshotting), convert timestamps in the timestamp converter. Expiry guide: JWT checks.
Why café becomes caf%C3%A9 (and spaces become %20)
URLs allow a small ASCII set; everything else percent-encodes as UTF-8 bytes — é is two bytes, hence %C3%A9. Spaces encode as %20 in paths but + in form bodies (application/x-www-form-urlencoded) — the #1 encoding bug I review. Encode &, = and # inside values or they split your query; never double-encode (%2520). URLs over ~2000 chars risk proxy truncation — POST the payload instead. Encode and parse safely with the URL encoder and URL parser. Encoding guide: URL encoding.
Limits and honest notes
Local tools inspect; they do not execute. Decoded JWTs are unverified until your backend checks signatures against the IdP keys. Hash comparisons catch corruption, not malice without a trusted channel. Regex testers validate patterns, not intent — a matching pattern can still be the wrong pattern. And no formatter fixes a 500 status: client-side validation narrows the suspect list, server logs close the case.
General guidance only. Never paste production secrets into any web tool you have not audited — ours runs locally, but verify in DevTools Network tab.