<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>KitBoxDev Blog</title><description>Practical guides to developer, DevOps and electrical-engineering tasks — written around tools that run entirely in your browser.</description><link>https://kitboxdev.com/</link><language>en</language><item><title>How to Use Browser-Private Tools for Cron, CIDR, YAML, JWT and Kubernetes</title><link>https://kitboxdev.com/blog/developers-devops-utility-guide</link><guid isPermaLink="true">https://kitboxdev.com/blog/developers-devops-utility-guide</guid><description>A step-by-step DevOps workflow built on client-side-only tools — cron parsing, CIDR maths, YAML and .env conversion, JWT debugging and Kubernetes resources.</description><pubDate>Sat, 22 Aug 2026 00:00:00 GMT</pubDate><category>devops</category><category>converter</category><category>network</category><category>crypto</category><author>KitBoxDev</author></item><item><title>JWT vs OAuth2 tokens: why claims matter for backend security</title><link>https://kitboxdev.com/blog/jwt-vs-oauth2-claims-backend-security</link><guid isPermaLink="true">https://kitboxdev.com/blog/jwt-vs-oauth2-claims-backend-security</guid><description>OAuth2 is a flow, JWT is a format — and neither one authorises anything. The claims your backend verifies and validates are what actually decide access.</description><pubDate>Sat, 22 Aug 2026 00:00:00 GMT</pubDate><category>crypto</category><category>decoder</category><category>generator</category><author>KitBoxDev</author></item><item><title>The KitBoxDev privacy-first manifesto: local processing, zero egress</title><link>https://kitboxdev.com/blog/privacy-first-manifesto-local-browser-processing</link><guid isPermaLink="true">https://kitboxdev.com/blog/privacy-first-manifesto-local-browser-processing</guid><description>Data-egress policy made third-party utility sites a compliance problem. Our answer is architectural — every tool runs in your browser, so credentials never leave the machine.</description><pubDate>Sat, 22 Aug 2026 00:00:00 GMT</pubDate><category>crypto</category><category>devops</category><category>reference</category><author>KitBoxDev</author></item><item><title>How to spot a misconfigured RS256 signature before deployment</title><link>https://kitboxdev.com/blog/spot-misconfigured-rs256-signature</link><guid isPermaLink="true">https://kitboxdev.com/blog/spot-misconfigured-rs256-signature</guid><description>RS256 fails quietly — the happy path verifies while the key, the PEM format or the algorithm allowlist is wrong. Here is how to catch it before it ships.</description><pubDate>Sat, 22 Aug 2026 00:00:00 GMT</pubDate><category>crypto</category><category>decoder</category><author>KitBoxDev</author></item><item><title>Verify, don&apos;t just trust: checking AI-generated cron jobs and infrastructure</title><link>https://kitboxdev.com/blog/verify-ai-generated-cron-and-infrastructure</link><guid isPermaLink="true">https://kitboxdev.com/blog/verify-ai-generated-cron-and-infrastructure</guid><description>An LLM will hand you a cron expression and a manifest that look right and run wrong. Here is the verification pass that catches them before a scheduler does.</description><pubDate>Sat, 22 Aug 2026 00:00:00 GMT</pubDate><category>devops</category><category>config</category><category>reference</category><author>KitBoxDev</author></item><item><title>KitBoxDev is live: 35 in-browser tools, built the way we wanted to use them</title><link>https://kitboxdev.com/blog/kitboxdev-launch-35-browser-tools</link><guid isPermaLink="true">https://kitboxdev.com/blog/kitboxdev-launch-35-browser-tools</guid><description>Why we built a tool platform with no backend, no accounts and no uploads — and what 35 finished tools, a 12 KB app shell and WCAG-audited contrast actually took.</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate><category>announcement</category><category>performance</category><category>accessibility</category><category>devops</category><author>KitBoxDev</author></item></channel></rss>