Skip to content

Verify that your input stays in the tab

You should not have to take our word for it. Here is the rule the server sends with every page, and three checks you can run yourself in about two minutes.

  • Free, no account
  • Nothing uploaded
  • 13 tools

The Content-Security-Policy this site sends

default-src 'self';script-src 'self';style-src 'self' 'unsafe-inline';img-src 'self' data: blob:;font-src 'self' data:;connect-src 'self';frame-src 'none';media-src 'self' blob:;worker-src 'self' blob:;manifest-src 'self';object-src 'none';base-uri 'self';form-action 'self';frame-ancestors 'none';

This text is generated from the same options object the server uses (src/lib/policy.ts, written to the _headers file when the site is built). The line that matters is connect-src 'self': scripts on these pages may open connections to parsing.tools and to nothing else.

Three checks, about two minutes

  1. 1 · Read the header

    Open DevTools (F12), go to Network, reload, click the first request (the page itself) and look under Response Headers for:

    content-security-policy: … connect-src 'self'; …
  2. 2 · Watch the network

    Keep Network open, choose the Fetch/XHR filter and clear the list. Paste something into any tool and use it. The list stays empty: formatting, decoding and hashing make no request. (Opening a tool for the first time loads its script, under the JS filter.)

  3. 3 · Try to break out

    In the Console, ask the page to contact another host:

    fetch('https://example.com/')

    The browser refuses and logs a message that the request violates the directive connect-src 'self'. Any script on this page would be refused the same way.

The header is added by the site's Worker in production. A local preview of the static files (for example vite preview) does not send it.

Nothing you paste is uploaded. The server sends connect-src 'self', so your browser blocks this page from contacting any other host. Check it yourself

What the tools store in your browser

WhatWhereUntil
Current input of each tool (up to 1,000,000 characters)sessionStorage, keys starting with pt:You close the tab
JWT, HMAC secret, text or file to hash, text pasted on the home pageMemory of the page onlyYou leave or reload the page
Text passed with "Send to" or "Open in"Memory of the page onlyThe next tool reads it
Input in a "Copy link" address (up to 12,000 bytes)The address, after #Wherever you paste the link

To see and clear it: DevTools → Application → Session storage → this site. There are no cookies set by the tools and no account.

What this does not cover

  • Browser extensions run with their own permissions and can read any page you open. A policy sent by a site does not restrain them.
  • The server receives ordinary request data for the pages and scripts it serves: your IP address, the path and your browser's user agent, as with any website.
  • Anyone you send a "Copy link" address to can read the input in it.

Questions

Short answers to what people ask most.

Can a web page really be prevented from sending data out?

A Content-Security-Policy is enforced by the browser, not by the page. With connect-src 'self', calls to fetch, XMLHttpRequest, WebSocket, EventSource and sendBeacon toward any other origin are blocked and logged in the console. The policy does not stop you from clicking a link or copying text yourself.

What about the site's own server?

The policy allows requests to parsing.tools itself, which is how the page loads its scripts. Whether a script sends your input there is something you can observe: in the Network panel, filter by Fetch/XHR and by method POST while you use a tool. The tools make no such request, and the Worker behind the site only serves static files, a health endpoint and a search-engine verification key.

Does the policy stay like this if ads or analytics are turned on?

No, and the pages would say so. The policy text on this page is generated from the same configuration the server uses. If that configuration ever allowed another host, the "connects only to this site" statements, which are derived from it, would no longer be shown.

Why use this bench

What is different here, and the code behind each claim.

The policy is connect-src 'self'
Set in the response headers from src/lib/policy.ts and enforced by your browser: scripts here cannot open a connection to another host.
No "save online"
The Worker serves static files, /api/health and a search-engine key file. There is no endpoint that accepts your text.
RegEx stops after 2 seconds
Patterns run in a Web Worker that is terminated on timeout, so catastrophic backtracking cannot freeze the page.
Tokens and secrets are not stored
The JWT decoder and the hash generator keep their input in memory only; other tools use sessionStorage, cleared when the tab closes.
Errors come with a position and a fix
JSON, YAML and XML errors give line and column, are underlined in the editor, and explain what to change.
Large inputs do not block typing
From 200,000 characters up, parsing moves to a Web Worker.