SECURITY

Built to keep payload work private

DevPayload separates local tool processing from deliberate cloud actions such as saving and sharing.

Local tool processing

JSON, JWT and PDF inputs are processed in the browser during normal tool use. They are not automatically sent to the server.

Account protection

Passwords are handled by ASP.NET Core Identity. Secure cookies, antiforgery protection, rate limiting and server-side authorization protect account operations.

Controlled sharing

Workspaces use GUID identifiers and are checked server-side. Only owners can grant Viewer or Editor access to an active registered user.

Browser security

Production responses include HSTS and restrictive content, framing, referrer and browser-permission policies.

Report a vulnerability

Please do not include passwords, access tokens or private payloads. Send a concise reproduction to the security contact.

security@devpayload.com
An unexpected error occurred. Reload×

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please retry or reload the page.