Skip to content
All projects

Personal · 2026

AirToolkit

Offline developer toolbox for air-gapped Windows machines: 38 utilities for JSON, crypto, certificates, networking and logs in one native Tauri app with zero unsolicited network calls.

Duration
About 4 weeks
Core stack
Tauri · Rust · React Js
Status
Completed
AirToolkit preview

Overview

AirToolkit is a free, open-source developer toolbox for Windows machines that cannot reach the internet. It bundles 38 everyday developer and IT utilities into one native desktop app that makes no network calls on its own: no telemetry, no auto-update, no CDN and no phone-home.

The idea came from my own work on internet-restricted VMs at a B2B security and access-control company, where a browser-based JSON formatter or regex tester is simply not an option. I designed and built the whole product: the desktop app, its offline verification process, the Windows installers and the product website.

The challenge

  • Air-gapped and locked-down machines cannot use the online tools developers rely on every day.
  • Many tools sold as offline still load analytics, font CDNs or update checks, which fail or phone home as soon as they are blocked.
  • Pasting a production JWT, a private key or a customer .env file into a website is unacceptable in a security-sensitive environment.
  • The app had to be small, fast and easy for IT teams to deploy, without accounts, license keys or downloads after installation.

What I built

38 tools in six categories

A searchable sidebar groups the tools by task:

  • Data & formats: JSON formatter, structural JSON diff, JSON Schema validation with ajv, JSON ↔ YAML / TOML conversion, XML / CSV and SQL formatters, sanitized Markdown preview.
  • Security & crypto: JWT decoder, hash and UUID generator, X.509 certificate decoder, certificate and CSR generator (RSA 2048/4096 or ECDSA P-256, keys generated locally), password strength checker.
  • Text, network and DevOps: encoders, string escaping, regex tester, diff, cURL ↔ request builder, subnet / CIDR calculator, cron explainer with the next run times, log parser, dotenv diff and a system info panel.
  • Files and media: hex inspector with magic-byte detection, Base64 file encoder, QR code generator and reader, favicon generator, colour palette extractor, fake data generator and a scratchpad.

One deliberate network exception

The API Request Tester is the only tool that sends traffic, and only a request the user composes, on demand, to a service on their own network. It is opt-in and flagged in its own interface, so the app itself still makes zero unsolicited calls.

Enterprise-ready distribution

Version 0.1.0 ships as a standard setup installer and an MSI package for Group Policy or SCCM deployment. Both can be copied onto an air-gapped machine and installed with no further downloads.

Product website

A separate Next.js site presents the tools, the security model, an FAQ and the downloads.

Architecture & security

  • Native shell: Tauri 2 with a Rust core instead of Electron, for a small installer, fast startup and low memory use. The release build is optimized with LTO and stripped symbols.
  • Everything bundled: fonts, libraries and assets ship inside the binary, so nothing is fetched at runtime.
  • Locked-down webview: a strict Content Security Policy limits scripts, styles and connections to the app itself.
  • Least-privilege capabilities: the HTTP permission is the only network capability granted, and it exists solely for the API Request Tester.
  • Static audit: a documented grep audit checks the frontend and Rust code for network primitives on every change; the only expected match is the API Request Tester.
  • Runtime check: a documented release procedure blocks the binary with a Windows Firewall rule and confirms that every other tool keeps working.

Tech stack

  • Desktop: Tauri 2, Rust, React 19, TypeScript, Tailwind CSS, Vite.
  • Key libraries: @peculiar/x509, ajv, js-yaml, @iarna/toml, sql-formatter, marked with DOMPurify, qrcode, jsQR, cron-parser, Faker.
  • Website: Next.js.

Outcome

  • A single native app that replaces a dozen online tools on machines that cannot reach them.
  • An offline claim backed by a reproducible audit, not just a promise.
  • An open-source project under the MIT licence, ready for IT teams to deploy through standard Windows tooling.
Next projectNeuroKey Password Manager