Paste an AWS IAM policy JSON to check for wildcard resources, overly broad actions, and full admin access. Everything runs locally in your browser — nothing is uploaded.
Decode Base64 strings and pretty-print JSON data — paste encoded text to see the decoded result instantly.
Query JSON data using dot-notation path expressions with wildcard support. Everything runs locally in your browser — nothing is uploaded.
Escape or unescape JSON strings — convert special characters to their JSON-safe escaped equivalents and back.
Convert messy CSV or Excel sheets from clients into clean JSON in one batch. Handles missing values, nested rows, and generates strict JSON schemas for 50+ files at once. Everything runs locally in your browser — nothing is uploaded.
Bidirectional YAML to JSON and JSON to YAML conversion with auto-format detection and real-time preview. Perfect for configuration files, API payloads, and data migration.
AWS IAM Policy Analyzer lets you paste an AWS IAM policy JSON to check for wildcard resources, overly broad actions, and full admin access. Everything runs locally in your browser — nothing is uploaded.. It works on any device with a modern web browser.
Paste an AWS IAM policy JSON to check for wildcard resources, overly broad actions, and full admin access. Everything runs locally in your browser — nothing is uploaded. It runs entirely in your browser — no software installation or data uploads required.
Paste or type your content directly into the provided text area.
Yes. After the initial page load, AWS IAM Policy Analyzer runs entirely on your device with no internet connection needed. All processing is done locally.
It flags wildcard resources (Resource: *), overly broad actions (Action: *), full admin access (AdministratorAccess), and policies that grant access to sensitive services like IAM, STS, or Organizations without restrictions.
Paste the IAM policy as valid JSON. This can be an inline policy, an attached managed policy, or the policy document from the AWS IAM console.
The analyzer focuses on IAM policy content — wildcard detection, action breadth, and resource scope. For SCP and permission boundary analysis, use the AWS Policy Simulator.
No. It identifies issues and provides recommendations. You must manually edit the policy in the AWS IAM console or via CLI to apply the suggested fixes.
No. All analysis runs locally in your browser. Your IAM policy JSON is never sent to any server.
Secret Scanner
Scan text and code for leaked secrets and credentials. Detects Stripe keys, GitHub tokens, Slack tokens, Google API keys, AWS keys, OpenAI keys, JWT tokens, private keys, and config passwords.
CVE Lookup
Look up Common Vulnerabilities and Exposures (CVE) by ID or keyword search. Everything runs locally in your browser — nothing is uploaded.