Secure Token Generator
Generate cryptographically secure random tokens in hex, Base64 or Base64URL for API keys and secrets.
Strong secret keys
API keys, JWT signing keys, session secrets, webhook signatures and password-reset tokens must be unpredictable. The Secure Token Generator creates them with your browser's cryptographically secure random generator (Web Crypto API).
Options
- 16, 32 or 64 bytes, or any custom length up to 1024 bytes
- Hex, Base64 or URL-safe Base64URL output
- Several tokens at once
Security
Generated tokens are never sent to a server, stored or logged. Still, don't commit secrets to your code repository; keep them in environment variables or a secret manager.
How to use Secure Token Generator
- Choose the token length in bytes.
- Pick the output format.
- Click "Generate".
- Copy the token and store it safely.
Why use this tool?
Generate secrets that meet security standards in seconds, without opening a terminal.
FAQ
How long should a secret key be?
32 bytes (256 bits) is a strong default for API keys, session secrets and HMAC keys.
When should I use Base64URL?
When the token goes into a URL or file name, prefer Base64URL, which has no + or / characters.
Can I use it as a password?
For user passwords the Strong Password Generator is more suitable; this tool is for machine-to-machine secrets.
Related tools
Strong Password Generator
Generate strong, unpredictable random passwords with the Web Crypto API.
Open toolUUID / GUID Generator
Generate random UUID v4 (GUID) identifiers in bulk for database keys and IDs.
Open toolULID Generator
Generate sortable, URL-safe, 26-character unique ULIDs and decode their timestamps.
Open toolHash Generator (MD5, SHA-256)
Calculate MD5, SHA-1, SHA-256, SHA-384 and SHA-512 hashes of text or files.
Open tool