🗝️ API Key & Secret Generator

Generates cryptographically random tokens suitable for API keys, session secrets or signing keys — using crypto.getRandomValues(). Bytes are generated locally; nothing is sent anywhere.

32 bytes = 256 bits, a common default for signing secrets.

Where the strength comes from

The slider sets a number of random bytes, filled by crypto.getRandomValues(). Every byte is uniform, so the entropy is exact rather than estimated, and the encoding changes only the length:

bits       = bytes x 8            32 bytes -> 256 bits
hex chars  = bytes x 2            32 bytes -> 64 characters
b64 chars  = ceil(bytes / 3) x 4  32 bytes -> 44 (43 unpadded)

The same 32 bytes as hex, Base64 or Base64URL are equally strong. Base64URL is the shortest and the only one safe to drop straight into a URL or header.

Picking a size and a prefix

Nothing is transmitted - the bytes are generated in your browser. That also means there is no copy to recover, so save a key before closing the tab.

Frequently asked questions

How long should an API key be?

32 random bytes covers everything. That is 256 bits, beyond any brute-force budget, and it is what most providers issue. Below 16 bytes you are relying on rate limiting.

Is hex or Base64 better for a secret key?

Neither is stronger - both encode the same bytes. Base64URL fits 256 bits into 43 characters instead of 64 and contains no +, / or =, so it survives URLs and filenames unescaped.

Is it safe to generate a production key in a browser?

The randomness is: crypto.getRandomValues() is the platform CSPRNG, the same source server-side code uses. The risk is the environment - clipboard managers, screen sharing and extensions can all see the value.