Constant-time string compare

Client

Compare two secrets in time independent of first mismatch position (educational).

Use format: first
---
second

Nearby workflows on Toolcore

  • Password strengthHeuristic password strength meter—length, charset mix, common weak-password warnings; local only. before you trust a token, digest, or key material in production.
  • HMAC (SHA-256 & more)HMAC-SHA-256/384/512/1 in the browser—hex or Base64 for webhooks, signing, and API docs. before you trust a token, digest, or key material in production.
  • Bcrypt hash & verifybcrypt password digests with adjustable cost (bcryptjs)—hash or verify $2a/$2b strings locally. before you trust a token, digest, or key material in production.
  • Hash identifierGuess digest type from hex length, Base64 shape, or bcrypt/Argon2 prefixes—heuristic, local only. before you trust a token, digest, or key material in production.

About this tool

Demonstrates length-then-XOR comparison—use platform crypto in production code.

Common use cases

  • Constant-time string compare for quick local checks without uploading data.
  • Copy results into tickets, docs, or classroom notes.

Common mistakes to avoid

  • Unexpected input shape

    See the intro and how-to notes for accepted formats.

FAQ

Is processing local?

Yes—this runs entirely in your browser.

Agent prefill?

Use q or qb for the main text field when supported.

Related utilities you can open in another tab—mostly client-side.