
Decode Base64, generate SHA hashes or work out what kind of hash you're looking at. Everything stays on your device.
Everything runs in your browser. Nothing you type is sent anywhere.
Look at its length and format. 32 hex characters is usually MD5 or NTLM, 40 is SHA-1, 64 is SHA-256 and 128 is SHA-512. Prefixes give others away: $2b$ is bcrypt, $argon2id$ is Argon2 and $6$ is SHA-512 crypt from Linux /etc/shadow.
Encoding (Base64, hex, URL encoding) changes how data is written and can always be reversed. Hashing turns data into a fixed-length fingerprint that can't be reversed. Neither is encryption, and encoded data is not secret.
No. Hashes are one-way. Weak or common passwords can still be guessed by hashing candidates and comparing, which is why passwords should be stored with slow hashes like bcrypt or Argon2, never MD5 or plain SHA.
No. Every encoding, hash and identification in this toolkit runs in your browser, so nothing you type leaves your device.