Developer / Security

API Key Generator (Random, Prefixed, Secure)

Generate cryptographically random API keys or secret tokens in your browser: choose the length, letters and digits, hex, or base64url characters, and an optional prefix such as sk_live_, and see the strength in bits.

API Key Generator (Random, Prefixed, Secure): Each character is picked by the browser's cryptographic random generator, with rejection sampling so that no character is more likely than another. Strength is length × log₂(number of characters): 32 letters and digits give 190 bits, 32 hex characters 128 bits. Anything above 128 bits cannot be guessed. Runs 100% locally in your browser with zero server file uploads.

Runs
In your browser
Cost
Free · no sign-up
Availability
Ready to use
API key generatorLocal processing

Runs entirely in your browser

190 bits of randomness per key

Keys come from your browser's cryptographic random number generator, with each character equally likely, and are never sent anywhere. Strength is the length times log₂ of the character count: 32 letters and digits give 190 bits. A prefix such as sk_live_ makes keys easy to recognise in code and lets secret scanners find leaked ones. Store only a hash of each key on the server, as you would a password.

Keys and UUIDs

A random UUID has 122 bits of randomness, enough for an identifier, but its fixed format makes it look like an ID rather than a secret. A key from this tool can be any length; for identifiers, use the UUID generator.

Storing keys

Because API keys are long and random, a fast hash such as SHA-256 is enough to store them safely; slow hashes like bcrypt are for human passwords. Hash a key with the hash generator to see what a server keeps.

How to use it

  1. Choose the length and the characters.
  2. Add a prefix if you want keys that are easy to recognise.
  3. Generate one or more keys and copy them.

Privacy & limitations

Keys are generated in your browser and never sent or stored.

Related tools

Frequently asked questions

How long should an API key be?

At least 128 bits of randomness: 22 letters and digits, 32 hex characters, or 22 base64url characters.

Why add a prefix?

A prefix such as sk_live_ shows what a key is for at a glance, and lets secret-scanning tools spot keys accidentally committed to code.

How should the server store keys?

Like passwords: keep a hash, such as SHA-256, and compare hashes; show the full key to its owner only once.

Free tool · runs in your browser · no account required