Developer Utilities API & Scraper
The Developer Utilities API returns 20+ deterministic developer and AI-agent tools as clean JSON.
🤖 Using an AI assistant? Copy this link into ChatGPT / Claude / Cursor — it reads every endpoint and parameter instantly and tells you if this API fits your use case.
The primary hash endpoint returns a value's hash across algorithms (hex, base64, base64url, bit length, HMAC), and the set covers UUIDs, encoding, JWT decode, password generation, cron parsing, slugify, regex testing, formatting and conversion. It is built for developer tools and AI agents that need one reliable endpoint for common utility operations without pulling in a dozen libraries. One ReefAPI key, one shared credit pool, the standard envelope.
Every action and the vocabulary it accepts
These are local computations, not fetches — a measured hash call returned in 2.2 ms and nothing leaves for a third-party site. What people actually need before writing a call is the exact list of values each action recognizes, so here it is.
| Action | Accepted values | Worth knowing |
|---|---|---|
| hash | md5 · sha1 · sha224 · sha256 (default) · sha384 · sha512 · sha3-256 · sha3-512 · blake2b · blake2s · crc32 · adler32 | hmac_key switches to a keyed HMAC digest; not valid for crc32/adler32 |
| uuid | v4 · v7 · v1 · v3 · v5 · ulid · nanoid | up to 100 per call; v3/v5 are deterministic and always return exactly 1 |
| encode | base64 · base64url · hex · url · url-component · url-form · html · unicode-escape · json-string | direction is encode or decode; url-component matches JS encodeURIComponent, url-form uses + for spaces |
| format | JSON · YAML · XML · SQL | pretty-print, minify or validate — string level, not files |
| convert | JSON · YAML · CSV · XML | string level, 512 KB ceiling |
| case_convert | camel · pascal · snake · kebab · constant · dot · title · sentence · upper · lower | reports the input casing it detected as well as converting |
| base_convert | any base 2–36 | 0x, 0b and 0o prefixes are detected, so from_base is optional |
| color | hex · rgb() · hsl() · CSS3 color name | returns every other format plus luminance and the nearest named color |
| qr | SVG · base64-PNG data URI · terminal ASCII | all textual output — nothing binary to handle |
| text_analyze | 97 languages detected | readability scores and profanity flags, algorithmic, no model involved |
| mock_data | 70+ Faker locales | preset bundles or a field-by-field schema |
| batch | up to 100 mixed calls | any combination of the actions above in one request |
Parameter names differ per action and most carry aliases, so hash accepts input, text, value or data for the same thing. When a name is wrong the response is an explicit MISSING_PARAM naming the parameter it wanted — passing user_agent to the user_agent action returns 'missing: input', because the payload parameter there is input.
Real request and response JSON
Captured from the indexed primary action, hash, on .
{
"method": "POST",
"url": "https://api.reefapi.com/dev-utils/v1/hash",
"headers": {
"x-api-key": "$REEF_KEY",
"content-type": "application/json"
},
"body": {
"input": "hello world",
"algo": "sha256"
}
}{
"ok": true,
"meta": {
"api": "dev-utils",
"endpoint": "hash",
"mode": "live",
"latency_ms": 56.1,
"record_count": 1,
"bytes": 0,
"cache_hit": false,
"algo": "sha256"
},
"data": {
"algo": "sha256",
"hex": "b94d27b9934d3e08a52e52d7da7dabfac484efe37a5380ee9088f7ace2efcde9",
"base64": "uU0nuZNNPgilLlLX2n2r+sSE7+N6U4DukIj3rOLvzek=",
"base64url": "uU0nuZNNPgilLlLX2n2r-sSE7-N6U4DukIj3rOLvzek",
"length_bits": 256,
"hmac": false,
"input_bytes": 11
}
}What the Developer Utilities API does
| Action | Description | Concrete use case | Key params |
|---|---|---|---|
| hash | Hash/checksum text or binary (base64/hex) input: md5…sha3·blake2·crc32·adler32, optional HMAC keying → hex + base64 digests. | Platform and DevOps teams call hash to get hash/checksum text or binary (base64/hex) input. | input, algo, hmac_key, input_encoding |
| uuid | Generate ids: uuid v4/v7/v1(MAC-safe)/v3/v5, ULID, nanoid — up to 100. | Security and supply-chain teams call uuid to generate ids. | version, count, namespace, name, size |
| encode | Encode/decode: base64(+url-safe), hex, URL (path/component/form), HTML entities, unicode-escape, json-string. | Developer-tool builders call encode to get encode/decode. | input, op, direction |
| jwt_decode | Decode a JWT WITHOUT needing the key (header+payload+claims analysis); optionally verify the signature with a provided key. Decode-only — this API never signs tokens. | AI-agent developers call jwt_decode to get decode a JWT WITHOUT needing the key (header+payload+claims analysis); optionally verify the…. | token, verify_key |
| password | Generate cryptographically-secure passwords (charset controls, ambiguity filter) + entropy strength score; or score a provided password with `check`. | Platform and DevOps teams call password to generate cryptographically-secure passwords (charset controls, ambiguity filter) + entropy st…. | length, count, lowercase, uppercase, digits, ... |
| cron | Explain a cron expression in plain language (15 locales) + compute the next N run times in any IANA timezone (DST-correct). | Security and supply-chain teams call cron to get explain a cron expression in plain language (15 locales) + compute the next N run times in an…. | expression, runs, tz, locale, from_time |
| slugify | URL-safe slug from any-script text (CJK/Cyrillic/Arabic → ASCII via anyascii transliteration). | Developer-tool builders call slugify to get uRL-safe slug from any-script text (CJK/Cyrillic/Arabic → ASCII via anyascii transliteration).. | input, separator, lowercase, max_length |
| regex_test | Test a regex against text: matches + groups + named groups, optional replace. User patterns run with a hard 1s timeout (ReDoS-guarded) + size caps. | AI-agent developers call regex_test to get test a regex against text. | pattern, input, flags, replacement, max_matches |
| format | Pretty-print, minify or validate JSON / YAML / XML / SQL (string-level; file/data CONVERSION lives in the file-convert API). | Platform and DevOps teams call format to get pretty-print, minify or validate JSON / YAML / XML / SQL (string-level; file/data CONVERSION…. | input, type, op, indent, sort_keys, ... |
| convert | Convert structured data between JSON / YAML / CSV / XML at the string level (paste-in, ≤512KB). CSV↔JSON is tabular (array of flat objects). For file/Excel/multi-MB conversion use the file-convert API. | Security and supply-chain teams call convert to convert structured data between JSON / YAML / CSV / XML at the string level (paste-in, ≤512KB). | input, from, to, indent, sort_keys |
| qr | Generate a QR code as SVG (text), base64-PNG (text data-URI), or terminal ASCII — all textual output, no binary asset. Up to QR version 40. | Developer-tool builders call qr to generate a QR code as SVG (text), base64-PNG (text data-URI), or terminal ASCII. | input, kind, error_correction, scale, border |
| color | Parse any CSS color (hex/rgb()/hsl()/name) → every format + CSS3 name + luminance; optional second color → WCAG 2.x contrast ratio + AA/AAA. | AI-agent developers call color to parse any CSS color (hex/rgb()/hsl()/name) → every format + CSS3 name + luminance; optional s…. | input, contrast_with |
| mock_data | Generate fake/test records (Faker, 70+ locales): preset bundles (person/address/company/internet/profile/product/lorem) or a custom field→type schema; seed for reproducible output. | Platform and DevOps teams call mock_data to generate fake/test records (Faker, 70+ locales). | preset, schema, count, locale, seed |
| text_diff | Unified diff between two texts + change stats + similarity ratio. | Security and supply-chain teams call text_diff to get unified diff between two texts + change stats + similarity ratio.. | a, b, context, label_a, label_b |
| text_analyze | Algorithmic text analysis (no LLM): language detect (97 langs) · readability (Flesch & co) · profanity flag/censor · keyword extraction · full stats. Pick checks or get all. | Developer-tool builders call text_analyze to get algorithmic text analysis (no LLM). | input, checks, top_keywords |
| timestamp | Parse/convert any timestamp ('now', unix s/ms/µs, ISO-8601, RFC-2822) → every format + timezone conversion + relative time. | AI-agent developers call timestamp to get parse/convert any timestamp ('now', unix s/ms/µs, ISO-8601, RFC-2822) → every format + timezo…. | value, tz |
| case_convert | Convert identifier/text casing: camel·pascal·snake·kebab·constant·dot·title·sentence·upper·lower (+ detected input case). | Platform and DevOps teams call case_convert to convert identifier/text casing. | input, target |
| base_convert | Convert integers between bases 2-36 (arbitrary precision; 0x/0b/0o prefixes accepted). | Security and supply-chain teams call base_convert to convert integers between bases 2-36 (arbitrary precision; 0x/0b/0o prefixes accepted).. | input, from_base, to_base |
| markdown | Render CommonMark+tables markdown → sanitized HTML (raw HTML escaped, XSS-safe) + heading TOC with slugs. | Developer-tool builders call markdown to render CommonMark+tables markdown → sanitized HTML (raw HTML escaped, XSS-safe) + heading TOC…. | input |
| user_agent | Parse a User-Agent string → browser/OS/device families + versions + bot flag (uap-core database). | AI-agent developers call user_agent to parse a User-Agent string → browser/OS/device families + versions + bot flag (uap-core databa…. | input |
| batch | Run up to 100 mixed dev-utils calls in one request. | Platform and DevOps teams call batch to get run up to 100 mixed dev-utils calls in one request.. | items |
Call hash from your stack
curl -X POST https://api.reefapi.com/dev-utils/v1/hash \
-H "x-api-key: $REEF_KEY" \
-H "content-type: application/json" \
-d '{"input":"hello world","algo":"sha256"}'import requests
r = requests.post(
"https://api.reefapi.com/dev-utils/v1/hash",
headers={"x-api-key": REEF_KEY},
json={
"input": "hello world",
"algo": "sha256"
},
)
print(r.json()["data"])const res = await fetch("https://api.reefapi.com/dev-utils/v1/hash", {
method: "POST",
headers: {
"x-api-key": process.env.REEF_KEY,
"content-type": "application/json",
},
body: JSON.stringify({
"input": "hello world",
"algo": "sha256"
}),
});
const { ok, data, meta, error } = await res.json();Ask your MCP-connected assistant: call reefapi.dev-utils.hash with {"input":"hello world","algo":"sha256"}.Who uses this API and why
- AI agents call these deterministic tools (hash, uuid, jwt_decode, cron) instead of guessing the result.
- Developer tools use encode, convert and format to normalize data inside a workflow.
- Automation pipelines use slugify, regex_test and password to handle common string operations reliably.
Questions developers ask before integrating
Can jwt_decode read a token without the signing key?
Yes, that is the point — header and payload are base64url, not encrypted. A measured decode of the standard HS256 sample returned header {alg: HS256, typ: JWT}, the payload, and claims with iat expanded to both unix 1516239022 and ISO-8601 2018-01-18T01:30:22+00:00. Note what signature_valid is in that case: null, not false. null means the signature was never checked; false would mean it was checked and failed. The response also carries trust: 'unverified' and an explicit warning string so an unverified decode cannot be mistaken for an authenticated one in a log.
Does this API sign or issue JWTs?
No. jwt_decode is decode-and-optionally-verify only. Pass verify_key with the HMAC secret for HS* or a PEM public key for RS*/ES*/PS* and the algorithm is taken from the token header against a whitelist — alg=none always fails verification rather than trivially passing, which is the classic JWT vulnerability. There is no signing action, deliberately: a signing key should never travel to somebody else's API.
What is the difference between UUID v4, v7 and ULID here?
v4 is pure random and sorts arbitrarily, which fragments a database index. v7 and ULID both embed a millisecond timestamp so ids generated close together sort close together; the response flags this as time_ordered: true. A measured batch of three v7 ids came back as 01a04005-30ca-74ca-…, 01a04005-30ca-72fa-… and 01a04005-30ca-72da-… — the shared leading segment is the timestamp. v1 is also timestamped but uses a random multicast node id, so the host MAC address never leaks into your ids. v3 and v5 are deterministic: same namespace plus name always yields the same UUID, so count is fixed at 1.
What does slugify do with Turkish, Chinese or Cyrillic text?
It transliterates to ASCII rather than dropping the characters. A measured call on 'Ürün Değerlendirmesi 2026 — 東京' returned slug 'urun-degerlendirmesi-2026-dongjing', and the response also exposes the intermediate transliterated form 'Urun Degerlendirmesi 2026 - DongJing' so you can see what happened. Turkish diacritics fold to their base letters, the em dash becomes a hyphen, and CJK is romanized. If a slug looks wrong, read transliterated first — the problem is almost always in that step, not the slug step.
Are cron next-run times timezone-correct?
Yes, and the offsets are in the output rather than implied. A measured call on '0 9 * * 1-5' with timezone Europe/Istanbul returned the description 'At 09:00, Monday through Friday', a fields breakdown of each of the five positions, and next_runs as fully-offset timestamps: 2026-08-27T09:00:00+03:00, 2026-08-28T09:00:00+03:00, then 2026-08-31 — correctly skipping the weekend. Any IANA zone name works, and the explanation is available in 15 locales.
Why does a crc32 hash return different fields than sha256?
Because a checksum and a cryptographic digest are different objects. A measured crc32 of 'hello world' returned hex '0d4a1185', decimal 222957957, base64 'DUoRhQ==', hmac false and input_bytes 11 — decimal is there because CRC values are conventionally compared as integers. The SHA and BLAKE families instead return length_bits and no decimal. Read the algo field before you index into the response, and never treat crc32 or adler32 as security primitives; they detect accidental corruption, not tampering.
How do I convert a number between bases without knowing the input base?
Pass the prefix. A measured base_convert of '0xFF' to base 2 returned output '11111111' and reported from_base 16, which it detected from the 0x — 0b and 0o work the same way. The response is not just the requested base either: it returns decimal '255', binary, octal and hex together plus bits: 8. Values are arbitrary precision, so a 300-digit integer converts without overflow, and decimal comes back as a string for that reason.
Can I tell a crawler apart from a real browser with user_agent?
Yes — the parse runs against the uap-core database and sets is_bot. A measured parse of Googlebot's own string returned browser {family: 'Googlebot', version: '2.1'}, device {family: 'Spider', brand: 'Spider', model: 'Desktop'}, os.family 'Other' with a null version, and is_bot true. The 'Other' os family is normal for crawlers rather than a parse failure — a bot string usually declares no operating system, so treat null version fields as absent data, not an error.
What is the Developer Utilities API?
Developer Utilities API is a ReefAPI endpoint group for developer utilities It returns live JSON through POST requests under /dev-utils/v1.
Is the Developer Utilities API free to try?
Yes. ReefAPI starts with 1,000 free credits, no card required. Developer Utilities calls use the same shared credit balance as every other ReefAPI engine.
Do I need a Developer Utilities login or account?
No login to Developer Utilities is needed for the API response. You call ReefAPI with your x-api-key header, and the playground can run live examples before you create a production key.
How fresh is the Developer Utilities data?
The page example is captured from a live hash call, and production requests fetch live data through ReefAPI rather than a static sample.
How many credits does the Developer Utilities API use?
Developer Utilities actions currently cost 1-2 credits per successful call. Failed or blocked calls are free, and all APIs draw from one credit pool.
Can I call Developer Utilities from an AI assistant or MCP client?
Yes. Connect ReefAPI once through MCP and your assistant can call dev-utils actions with the same key, credit pool and JSON envelope used by normal REST requests.