Skip to content
ToolSuite

JavaScript Scratchpad

Run a snippet of JavaScript in an isolated sandbox and see the console output.

Processed in your browser

Fill in the form and press “Run code” to see the result here.

How to use it

  1. 1Write or paste your snippet.
  2. 2Press Run. The code executes inside a sandboxed frame, never on a server.
  3. 3Use console.log to print, or end with an expression to see its value.

About the JavaScript Scratchpad

Your code never reaches a server. There is no server-side execution anywhere in this tool, which removes the entire class of risk that comes with remote code evaluation.

It runs inside an iframe with `sandbox="allow-scripts"` and no `allow-same-origin`. The frame has an opaque origin, so the code cannot read this page or its DOM, cannot touch cookies or local storage, cannot make requests carrying your credentials, and cannot navigate or open the parent window.

console.log, console.warn and console.error are captured and printed, and the value of the final expression is shown if there is one. Errors are caught and displayed rather than disappearing.

The sandbox is reset on every run, so nothing persists between executions.

Questions people ask

Does my code run on your server?

No, and it never will. Running visitor-supplied code on a server is a remote code execution vulnerability by design. Everything here executes in your own browser, inside a frame that is isolated from this page.

Can the code I paste steal my session on other sites?

No. The frame has an opaque origin, so it has no access to cookies, storage or pages belonging to any origin - including this one. Still, do not paste code containing real credentials into any online editor.

Can I use fetch or import a library?

Network access from the frame is restricted by this site’s Content-Security-Policy, so external requests and remote imports will not load. It is a scratchpad for logic, not a full development environment.

Is any of this information sent anywhere?

No. Every value is read from your browser by JavaScript running in this page and displayed locally. Nothing is transmitted, logged or stored.

Is it free, and do I need an account?

Yes, it is free, and there is no account, no sign-up and no watermark on the result. The project is funded by optional donations.