Local tool processing
JSON, JWT and PDF inputs are processed in the browser during normal tool use. They are not automatically sent to the server.
DevPayload separates local tool processing from deliberate cloud actions such as saving and sharing.
JSON, JWT and PDF inputs are processed in the browser during normal tool use. They are not automatically sent to the server.
Passwords are handled by ASP.NET Core Identity. Secure cookies, antiforgery protection, rate limiting and server-side authorization protect account operations.
Workspaces use GUID identifiers and are checked server-side. Only owners can grant Viewer or Editor access to an active registered user.
Production responses include HSTS and restrictive content, framing, referrer and browser-permission policies.
Please do not include passwords, access tokens or private payloads. Send a concise reproduction to the security contact.
security@devpayload.com