Generate CSPRNG code verifiers and SHA-256 Base64URL code challenges.
Execution runs 100% locally inside the browser sandbox using HTML5 Canvas, Web Cryptography Subtle API, and Web Workers. Zero egress.
Zero network latency. Operates completely offline with zero dependencies on third-party backend servers or cloud services.
Built according to official RFC specifications, cryptographic test vectors, and enterprise-grade data transformation standards.
Choose verifier string length (43 to 128 characters).
Click Regenerate to create a fresh cryptographic verifier and challenge.
Copy the code verifier to your auth session and challenge to your authorization URL.
Proof Key for Code Exchange (PKCE) prevents authorization code interception attacks on public clients (mobile apps, SPAs).
Yes, it uses window.crypto.getRandomValues() CSPRNG and Web Crypto Subtle SHA-256 hashing.
Zero-egress companion tools in the Security & Network suite
Measure cryptographic randomness, Shannon entropy (0-8 bits/byte), Chi-square test, and byte distributions.
Brute-force all 256 single-byte XOR keys with automated English frequency & chi-squared scoring.
Audit CSP, HSTS, X-Frame-Options, and security headers with OWASP grading (A+ to F).
Compare memory hardness, GPU ASIC resistance, and security parameters across KDF standards.