Back

Free tools

Small tools, no signup.

The checks we run constantly, as standalone utilities. Everything runs in your browser, nothing is stored.

Coming soon

JWT decoder

Paste a token, read its header, claims and expiry. Decoded in your browser, never sent anywhere.

Coming soon

Security headers

Check a URL for the headers that matter, and see which of them are missing or set too loosely.

Coming soon

CORS checker

Find out whether an origin you do not control can read responses from your API.

Coming soon

CSP generator

Build a Content Security Policy that fits your app, with an explanation of every directive.

Run all of this against your own app.

These are single checks. GhostRecon runs the whole set continuously against your live app, then verifies every finding before it reports it.

Download for Mac