🗝️ API Key & Secret Generator
Generates cryptographically random tokens suitable for API keys, session secrets or signing
keys — using crypto.getRandomValues(). Bytes are generated locally; nothing is
sent anywhere.
Where the strength comes from
The slider sets a number of random bytes, filled by
crypto.getRandomValues(). Every byte is uniform, so the entropy is
exact rather than estimated, and the encoding changes only the length:
bits = bytes x 8 32 bytes -> 256 bits
hex chars = bytes x 2 32 bytes -> 64 characters
b64 chars = ceil(bytes / 3) x 4 32 bytes -> 44 (43 unpadded)
The same 32 bytes as hex, Base64 or Base64URL are equally strong. Base64URL is the shortest and the only one safe to drop straight into a URL or header.
Picking a size and a prefix
- 16 bytes (128 bits) is the floor for anything long-lived; 32 bytes (256 bits) is the usual default for HMAC signing secrets. The 8-byte end of the slider is 64 bits - an identifier, not a credential.
- The prefix adds no entropy. A tag like
sk_live_exists so people and secret-scanning bots can tell what leaked, and from which environment.
Frequently asked questions
How long should an API key be?
32 random bytes covers everything. That is 256 bits, beyond any brute-force budget, and it is what most providers issue. Below 16 bytes you are relying on rate limiting.
Is hex or Base64 better for a secret key?
Neither is stronger - both encode the same bytes. Base64URL fits 256 bits into
43 characters instead of 64 and contains no +, / or
=, so it survives URLs and filenames unescaped.
Is it safe to generate a production key in a browser?
The randomness is: crypto.getRandomValues() is the platform
CSPRNG, the same source server-side code uses. The risk is the environment -
clipboard managers, screen sharing and extensions can all see the value.