The Web Crypto API (crypto.subtle) is one of the most under-appreciated browser features. It provides standards-based primitives — SHA-256 hashing, AES-GCM encryption, HMAC, and PBKDF2 key derivation — without any third-party library. That matters for local-first tools: integrity checks, checksums, and key generation can happen entirely on the device.

What it does well

For a local tool, the most useful operations are:

Related reading: How to Remain Valuable When Intelligence Becomes Cheap — a 224-page practical book on staying valuable as intelligence gets cheap. $3.84. Read it on Gumroad →

  • Hashing. crypto.subtle.digest('SHA-256', data) returns a digest of any buffer. Use it to verify file integrity, deduplicate content, or compare two inputs without revealing them.
  • Key generation and encryption. AES-GCM provides authenticated encryption. Combined with PBKDF2, you can derive a key from a passphrase and encrypt data that never leaves the page.
  • Randomness. crypto.getRandomValues() is the correct source of randomness for generating tokens, UUIDs, and passwords — far better than Math.random() for anything security-related.

What it cannot do

This is the part that matters. Hashing in the browser does not authenticate anyone. If a client sends a SHA-256 digest to a server, the server has no way to know who computed it. Client-side hashing is useful for integrity and local checks, not for identity.

Similarly, a JavaScript encryption scheme that ships its key in the same page can be read by anyone who inspects the page. "Encrypted in the browser" protects against casual interception of data at rest on the same device — it does not make a public web page a secure vault.

Two practical rules

  • Use Web Crypto for what it is: a clean, auditable set of primitives for local work.
  • Never roll your own protocol on top of it. Use well-understood constructions — or better, a purpose-built tool — and let the browser handle the primitives.

If you want to see these ideas in practice, the Hash Type Identifier and Entropy & Randomness Analyser tools on this site work entirely locally with these exact primitives.