HSM Kit

Lokaler MCP-Server für Base64-, Luhn-, Schlüsselkomponenten-XOR- und synthetische ISO-0-PIN-Block-Tools.

Dokumentation

HSM Kit - Professional Online Encryption Toolkit

HSM Kit Logo

🔐 Professional encryption & key management tools, 100% client-side, secure & reliable

Website License React TypeScript Tests

English | 简体中文 | 日本語 | 한국어 | Deutsch | Français


📖 Introduction

HSM Kit is a professional online encryption toolkit designed for developers, testers, and security engineers in finance, payment, and security domains. It provides 44+ tools covering HSM key management, payment security, PKI certificates, and cryptographic algorithms, all running entirely in the browser.

Core Values

  • Security First - 100% client-side computation, keys and sensitive data never leave your device
  • Professional & Complete - 44+ tools covering HSM key management, payment security, PKI certificates, and cryptographic algorithms
  • Ready to Use - Open browser and start working, supports PWA installation, works on Mac/Windows/Linux/mobile
  • Open Source - Code is publicly auditable, meets financial industry compliance requirements

✨ Features

FeatureDescription
🔒 Local ComputationAll crypto operations run in browser, data never uploaded
📱 PWA SupportInstallable to desktop, works like native app, offline available
🌐 Cross PlatformMac/Windows/Linux/iOS/Android supported
🌍 Multi-languageEnglish, Chinese, Japanese, Korean, German, French - 100% coverage
🌙 Dark ModeDay/night theme switching to protect your eyes
♿ AccessibleARIA labels, keyboard navigation, skip-to-content, aria-live regions, WCAG 2.1 AA compliant
⚡ Lazy LoadingRoute-level code splitting, only loads current page
🔍 SEO OptimizedPre-rendered static HTML, Schema markup, multi-language hreflang
📚 Knowledge Base43 English + 43 Chinese technical articles with static, indexable delivery
🇨🇳 Localized Tool URLs8 high-demand tools have canonical Chinese URLs with reciprocal hreflang
🧪 Published Test VectorsDownloadable AES JSON vectors verified by CryptoJS and Web Crypto regression tests
📝 Context-safe ExamplesOne-click examples preserve the selected mode, format, tab, and enabling toggles
✅ Consistent Input ValidationShared gray/green/red length and format states across all tool inputs
⭐ Favorites & Recent ToolsLocal favorites plus 90-day recent-tool history, with no account required
🔗 Workflow DiscoveryEach tool links to the next relevant tools and its supporting guides
📊 Privacy-safe EventsOptional GA/Zaraz events contain action/tool IDs only, never form values or results
🧪 Test Coverage100+ Vitest tests plus production page smoke checks for all 44 tools

🛠️ Tool Modules

🔐 Encryption/Decryption Tools (5)

ToolDescriptionRoute
AES EncryptionAES-128/192/256, ECB/CBC/CFB/OFB/CTR modes/aes-encryption
DES/3DES EncryptionDES/Triple DES, multiple padding options/des-encryption
RSA EncryptionRSA encrypt/decrypt/sign/verify, PKCS#1/OAEP/rsa-encryption
ECC/ECDSAElliptic curve, secp256k1/P-256/P-384/ecc-encryption
FPE Format-PreservingFF1/FF3-1 algorithms, NIST SP 800-38G/fpe-encryption

🔑 Key Management Tools (8)

ToolDescriptionRoute
Key GeneratorAES/DES/3DES secure random keys, key combining, parity/keys-dea
Keyshare GeneratorKey splitting for secure custody, KCV calculation/keyshare-generator
Futurex KeysFuturex HSM key encrypt/decrypt/lookup/futurex-keys
Atalla Keys (AKB)Atalla AKB format key encrypt/decrypt/atalla-keys
SafeNet KeysSafeNet HSM key encrypt/decrypt/lookup/safenet-keys
Thales KeysThales HSM LMK key encrypt/decrypt/lookup/thales-keys
Thales Key BlockThales proprietary key block encode/decode/thales-key-block
TR-31 Key BlockANSI X9.143 key block encode/decode/tr31-key-block

🔐 PKI Tools (2)

ToolDescriptionRoute
ASN.1 DecoderDER/BER structure decoding, X.509 certificate parsing/asn1-parser
SSL Certificates (X509)SSL/TLS certificate parsing & validation/ssl-certificates

💳 Payment Security Tools (21)

CategoryToolRoute
AS2805AS2805 Message Tool/payments-as2805
BitmapISO 8583 Bitmap/payments-bitmap
Card ValidationCVV/CVC/payments-card-validation-cvvs
Card ValidationAMEX CSC/payments-card-validation-amex-cscs
Card ValidationMasterCard CVC3/payments-card-validation-mastercard-cvc3
DUKPTDUKPT TDES (ISO 9797)/payments-dukpt-iso9797
DUKPTDUKPT AES/payments-dukpt-aes
MACISO 9797-1 MAC/payments-mac-iso9797-1
MACANSI X9.9/X9.19/payments-mac-ansix9
MACAS2805 MAC/payments-mac-as2805
MACTDES CBC-MAC/payments-mac-tdes-cbc-mac
MACHMAC/payments-mac-hmac
MACCMAC/payments-mac-cmac
MACRetail MAC/payments-mac-retail
PINPIN Block General/payments-pin-blocks-general
PINPIN Block AES/payments-pin-blocks-aes
PINPIN Offset/payments-pin-offset
PINPIN PVV/payments-pin-pvv
OtherVISA Certificates/payments-visa-certificates
OtherZKA (German Banking)/payments-zka

🧰 General Tools (9)

ToolDescriptionRoute
Hash CalculatorMD5/SHA/SHA-3/BLAKE2/SM3 20+ algorithms/hashes
Character EncodingASCII/Hex/Binary/EBCDIC/ATM conversion/character-encoding
BCD EncodingDecimal to BCD encoding conversion/bcd
Check DigitsLuhn (MOD 10) / Amex SE (MOD 9)/check-digits
Base64 Encode/DecodeStandard Base64 encoding/decoding/base64
Base94 Encode/DecodeBase94 encoding/decoding/base94
Message ParserISO 8583, ATM NDC/Wincor parsing/message-parser
RSA DER Public KeyRSA public key DER/PEM encode/decode/rsa-der-public-key
UUID GeneratorUUID v1/v3/v4/v5 generation/uuid

📚 Knowledge Base

HSM Kit includes a built-in knowledge base (/guides/) with 42 in-depth technical articles in each of English and Chinese, covering encryption algorithms, payment security, HSM key management, and more. Articles are cross-linked and directly connected to corresponding tools.

Knowledge Base Features

  • 📝 Markdown Rendering - Code blocks, tables, internal links
  • 🔗 Tool Integration - Direct links to related tools and articles
  • 🌍 Bilingual - English and Chinese, 43 articles each, fully translated
  • 📖 Table of Contents - Right-side TOC navigation with scroll highlighting
  • 🔍 Search - Full-text search across articles

📁 Project Structure

hsmkit/
├── public/                     # Static assets
│   ├── favicon.svg             # Website logo
│   ├── favicon-*.png           # PWA icons (48/192/512)
│   ├── apple-touch-icon.png    # iOS icon
│   ├── sitemap.xml             # Sitemap (144 URLs with hreflang)
│   ├── robots.txt              # Crawler instructions
│   ├── _headers                # HTTP headers (Cloudflare)
│   └── _redirects              # SPA route redirects
│
├── scripts/                    # Build scripts
│   ├── generate-favicon-png.js # Favicon generation
│   ├── generate-guide-og.js    # Per-guide social image generation
│   ├── prerender-guides.js     # Static guide-page generation
│   ├── check-tool-pages.js     # Production page smoke checks
│   └── update-sitemap-lastmod.js # Guide/tool sitemap maintenance
│
├── src/
│   ├── components/             # Reusable components
│   │   ├── cipher/             # Encryption tool components
│   │   ├── common/             # Common components
│   │   │   ├── PageLayout.tsx  # Page layout + Schema.org
│   │   │   ├── ToolPage.tsx    # Tool page factory
│   │   │   ├── SEO.tsx         # SEO meta tags + prerender
│   │   │   ├── ResultCard.tsx  # Result display (aria-live)
│   │   │   ├── ErrorCard.tsx   # Error display (role="alert")
│   │   │   ├── LengthIndicator.tsx # Shared input length/format states
│   │   │   ├── ExampleButton.tsx # Context-preserving example loading
│   │   │   ├── ErrorBoundary.tsx # Error boundary
│   │   │   ├── ReloadPrompt.tsx # PWA update prompt (dark mode)
│   │   │   └── ...
│   │   ├── generic/            # General tool components
│   │   ├── keys/               # Key management components
│   │   ├── payment/            # Payment tool components
│   │   └── pki/                # PKI tool components
│   │
│   ├── hooks/                  # Custom hooks
│   │   ├── useLanguage.tsx     # Multi-language switching
│   │   ├── useTheme.tsx        # Theme switching
│   │   ├── useToolForm.ts      # Tool form hook
│   │   ├── useRecentTools.ts   # Recent tools and local favorites
│   │   └── ...
│   │
│   ├── data/                   # Tool metadata and examples
│   │   ├── examples.ts         # Non-production example values
│   │   ├── toolRelations.ts    # Related-tool workflow graph
│   │   └── toolGuidesMap.ts    # Tool-to-guide links
│   │
│   ├── locales/                # Translations (6 languages)
│   │   ├── en/                 # English
│   │   ├── zh/                 # Chinese
│   │   ├── ja/                 # Japanese
│   │   ├── ko/                 # Korean
│   │   ├── de/                 # German
│   │   └── fr/                 # French
│   │
│   ├── utils/                  # Utility functions
│   │   ├── analytics.ts        # Privacy-safe tool action events
│   │   ├── crypto.ts           # Core crypto utilities
│   │   ├── crypto.test.ts      # Crypto unit tests
│   │   ├── hex.ts              # Hex utilities
│   │   ├── hex.test.ts         # Hex unit tests
│   │   ├── logger.ts           # Production-safe logger
│   │   └── ...
│   │
│   ├── App.tsx                 # Root component + routes
│   ├── routeConfig.ts          # Route configuration
│   ├── routes.tsx              # Lazy-loaded page components
│   └── main.tsx                # Entry point
│
├── vitest.config.ts            # Test configuration
├── vite.config.ts              # Build configuration
├── tsconfig.json               # TypeScript config (strict mode)
└── package.json                # Dependencies

🚀 Quick Start

Online

Visit https://hsmkit.com to use all tools directly.

PWA Install

After visiting the website, your browser will prompt "Install HSM Kit". Click to install to desktop.

Local Development

# Clone repository
git clone https://github.com/hsm-kit/hsmkit.git
cd hsmkit

# Install dependencies
npm install

# Start development server
npm run dev
# Visit http://localhost:5173

Build for Production

# Build (includes sitemap update + Puppeteer prerender + PWA Service Worker)
npm run build

# Preview production build
npm run preview

When a release changes tool-page functionality, refresh only the 44 tool-page dates without rewriting homepage, legal, or guide dates:

node scripts/update-sitemap-lastmod.js --tools-date YYYY-MM-DD

Note: Chrome is required for building. The prebuild script automatically installs it via npx puppeteer browsers install chrome.

Type Checking

# TypeScript type checking (strict mode)
npm run typecheck

# ESLint code checking
npm run lint

# ESLint auto-fix
npm run lint:fix

Testing

# Run all tests
npm test

# Smoke-test every generated tool and guide page
npm run test:pages

# Watch mode
npm run test:watch

# Test coverage
npm run test:coverage

🏗️ Tech Stack

TechnologyVersionPurpose
React19Frontend framework
TypeScript5.9Type safety (strict mode)
Vite (Rolldown)7.2Build tool
Ant Design6UI component library
React Router7Routing
CryptoJS4.2Symmetric encryption (AES/DES/3DES)
node-forge1.3RSA/ASN.1/X.509
elliptic6.6ECC/ECDSA
hash-wasm4.12High-performance hashing (WASM)
react-markdown10.xMarkdown rendering
vite-plugin-pwa1.3PWA support (Service Worker)
Vitest4.xUnit testing framework
@testing-library/react16.xReact component testing

⚡ Performance

OptimizationDescription
Route Lazy LoadingAll pages use React.lazy() for on-demand loading
Vendor SplittingReact / Ant Design / Crypto packaged separately for caching
Pre-rendering SSGPuppeteer generates static HTML at build time
Hydration ReuseUses hydrateRoot when pre-rendered HTML exists
PWA CachingService Worker pre-caches 210+ resources for offline use
Long-term CachingStatic assets max-age=31536000, immutable

🔐 Security

  • Client-side Encryption - All crypto operations run in browser using Web Crypto API and crypto-js
  • Zero Data Transfer - Keys and sensitive data never leave your device
  • Open Source - All code is publicly auditable
  • Compliance Ready - Meets financial industry security requirements
  • CSP Protection - Content-Security-Policy prevents XSS attacks
  • Production Logging - Debug logs silenced in production, only errors recorded

♿ Accessibility

HSM Kit follows WCAG 2.1 AA standards with comprehensive accessibility support:

  • Skip-to-content Link - Keyboard users can quickly jump to main content
  • ARIA Labels - Navigation, buttons, form elements have proper aria-labels
  • aria-live Regions - Dynamic results and errors are announced by screen readers
  • Keyboard Navigation - All interactive elements support Tab/Enter/Space
  • Focus Management - Clear focus indicators and logical focus order
  • Semantic HTML - Uses role="banner", role="main", role="alert" etc.

🌍 Internationalization

HSM Kit supports 6 languages with 100% translation coverage:

LanguageCodeStatus
Englishen✅ 100%
简体中文zh✅ 100%
日本語ja✅ 100%
한국어ko✅ 100%
Deutschde✅ 100%
Françaisfr✅ 100%

Translation files are located in src/locales/ with lazy loading for optimal performance.


🌍 Deployment

HSM Kit can be deployed to any static hosting service:

PlatformConfig File
Cloudflare Pageswrangler.json, public/_headers, public/_redirects
Vercelvercel.json
Netlifypublic/_redirects
# The dist/ directory can be deployed directly after build
npm run build

Search Discovery

  • Set BING_SITE_AUTH in the build environment to the verification value supplied by Bing Webmaster Tools.
  • After Cloudflare Pages finishes deploying, open GitHub Actions → Submit URLs to IndexNow → Run workflow. Leave the URL empty to submit the sitemap, or enter one changed URL. Local submission remains available through npm run submit:indexnow.
  • AI-readable resources are published at /llms.txt, /ai/tools.json, and each guide's index.md URL.

🤝 Contributing

Welcome to submit Issues and Pull Requests!

  1. Fork this repository
  2. Create a feature branch (git checkout -b feature/AmazingFeature)
  3. Commit your changes (git commit -m 'Add some AmazingFeature')
  4. Push to the branch (git push origin feature/AmazingFeature)
  5. Submit a Pull Request

Adding New Knowledge Base Articles

  1. Create {slug}.md in src/content/guides/en/ (and zh/ for Chinese)
  2. Update src/data/guides/en.json and zh.json with metadata
  3. Add routes in prerender.config.ts
  4. Add URL in public/sitemap.xml
  5. Run npm run build to verify

📄 License

MIT License - See LICENSE file


🔗 Links


⚠️ Note: This tool is intended for testing and development environments. Please ensure compliance with relevant security standards before using in production.

Made with ❤️ by HSM Kit Team