Generate high-entropy API keys and secrets in your browser.
🔒 Generated with crypto.getRandomValues — your browser's CSPRNG — entirely on this device; nothing is uploaded. Alphanumeric output uses rejection sampling so every character is uniformly distributed (no modulo bias). Store generated secrets in a password manager or your platform's secrets store, and rotate any key that ever appears in logs, tickets, or screenshots.
This tool generates high-entropy secrets — API keys, access tokens, webhook secrets, signing keys, or one-time setup passwords — using crypto.getRandomValues, your browser's cryptographically secure random number generator. Pick a format (hex, Base64, Base64URL, alphanumeric, an API-key style string with your own prefix, or UUID v4), set the length, and generate one secret or a batch of five or ten. Everything happens 100% on your device: nothing is logged, stored, or uploaded.
Entropy measures how many guesses an attacker would need, on average, to find your secret. As a rule of thumb: below 80 bits is weak (fine for short-lived codes, not for keys), 80–128 bits is good for most tokens, and above 128 bits is strong — the right territory for signing keys and long-lived API secrets. The tool labels each result Weak / Good / Strong so you can sanity-check at a glance. For byte-based formats the math is simple: bytes × 8 bits, so 32 random bytes give a full 256 bits. Alphanumeric strings carry about 5.95 bits per character (log₂ of 62 symbols), so you need ~22 characters to beat 128 bits.
Hex is the classic for HMAC keys and anything copied into config files; Base64URL packs the same entropy into fewer characters and survives URLs and headers without escaping, which is why JWT secrets and OAuth tokens often use it. Alphanumeric avoids punctuation entirely — handy when a picky system rejects symbols. The API key style adds a human-readable prefix like sk_live_ so keys are recognizable in dashboards and leak scanners (the prefix adds no entropy — that all comes from the random suffix). UUID v4 is for identifiers that must be unique and opaque, not for secrets: at 122 bits it is fine as a token, but its real job is ID generation.
A naive way to pick random characters is byte % 62 — but 256 is not a multiple of 62, so a few characters become slightly more likely than others. That skew is called modulo bias, and while small, it is exactly the kind of flaw that weakens keys at scale. This generator discards any random byte ≥ 248 (the largest multiple of 62 that fits in a byte) and draws again, so every character is perfectly uniform. The byte-based formats need no such correction: each byte is used whole. Two parting tips: generate secrets fresh per environment (never reuse one across dev and prod), and rotate immediately if a key ever lands in a log, email, or screenshot.
The Secret Key Generator creates secret key generator on demand, right in your browser. Set the options you need, click generate, and the result is ready to copy. Because everything runs locally, nothing you enter or produce leaves your device.
Generators like this are useful when you need a specific output (a password, a UUID, a QR code, placeholder text) and don't want to install an app or trust an unknown website with your data. This tool is free, has no usage limits, and works the same on phone and desktop.
Common uses: people reach for this tool when they need to use a random api key generator online, generate secret key for jwt, cryptographically secure token generator, or hex secret key generator.
Browser-based tools like this one have a few real advantages over installed software or manual methods:
The Secret Key Generator is based on the following formula:
keyspace bits = log₂(charset^length) = length × log₂(charset) bytes for a 256-bit key = 256 ÷ 8 = 32
Variables: keyspace bits: information content of the generated key (bits) charset: number of distinct symbols in the format (16 for hex, 64 for Base64, 95 for printable ASCII) length: number of characters in the key bytes: raw key material, 8 bits per byte
A random key of a given length over a fixed alphabet has as many possible values as charset^length, and log₂ of that count is its strength in bits. Different encodings of the same random bytes (hex doubles the length, Base64 multiplies by 4/3) carry identical security.
Worked example: Step 1: A 64-character hex key uses a charset of 16. Step 2: keyspace bits = 64 × log₂(16) = 64 × 4 = 256 bits. Step 3: 256 bits ÷ 8 = 32 bytes of raw key material. Result: a 64-character hex key carries the same 256-bit strength as 32 random bytes.
More tools you might find useful