Random Token Generator

Generate secure random tokens for API keys, session secrets, and reset links. Choose the length, the characters, and an optional prefix such as sk_live_.

Updated
Generated in your browser with Web Crypto. Never sent or stored.
Tokens
    Uses crypto.getRandomValues.

    How to use the Random Token Generator

    1. Set the Length and How many tokens you need.
    2. Pick the Characters. Use Hex or Base64URL for secrets in URLs and config files, or Custom for your own set. Add a Prefix if your keys have one.
    3. Press Generate and copy one token or the whole list.

    How it works

    • Every character is chosen with crypto.getRandomValues, your browser's cryptographically secure generator, using rejection sampling so each character is equally likely.
    • Entropy = length × log2(number of characters in the set). The prefix adds nothing, because it is the same on every token.
    • A 32-character hex token has 32 × 4 = 128 bits. A 32-character Base64URL token has 32 × 6 = 192 bits.
    • Custom sets have duplicate characters removed before generating.

    Examples

    • 32 hex characters: 128 bits, the same strength as a random UUID's 122 bits plus a little more. Good for session secrets.
    • 43 Base64URL characters: about 258 bits, enough for any API key.
    • Prefix sk_live_ with 24 alphanumeric characters gives keys like sk_live_ + 24 characters, about 143 bits, and makes leaked keys easy to spot in code scans.

    Limitations

    • Tokens are not stored. Copy them before leaving the page.
    • Tokens are random strings, not signed. If you need data inside a token, use a JWT or a signed cookie instead.
    • Store API keys hashed on your server (for example with SHA-256) so a database leak doesn't expose them.

    Frequently asked questions

    How long should an API key be?

    At least 128 bits of entropy: 32 hex characters, 22 Base64URL characters, or 22 letters and digits. More doesn't hurt.

    Is Math.random() good enough for tokens?

    No. It is predictable. This tool uses crypto.getRandomValues, which is designed for secrets.

    Why add a prefix to API keys?

    A fixed prefix such as sk_live_ tells people and secret scanners what the key is, so a leaked key in a repository gets caught quickly.

    Are the tokens sent to your server?

    No. They are generated in your browser and never leave it.

    Often used together with the Random Token Generator.