API Key & Token Generator

Create strong random keys and tokens for APIs, webhooks, sessions and signing secrets. They are generated in your browser and never sent to us.

Runs in your browser — nothing is uploaded
Bytes for hex/Base64; characters for the others.

Keys

Generated with the Web Crypto API on your device. Nothing is stored or sent.

How to use API Key & Token Generator

  1. Choose a format and length (32 bytes = 256 bits is a good default).
  2. Optionally add a prefix such as sk_live_ and choose how many to generate.
  3. Copy the keys and store them in your secret manager.

Questions

How long should an API key be?

At least 128 bits of randomness; 256 bits (32 bytes, e.g. 64 hex characters) is a common choice for secrets and signing keys and is far beyond brute-force reach.

Are these keys secure?

They come from the Web Crypto API (crypto.getRandomValues), the browser’s cryptographically secure random generator, with unbiased character selection. They are created on your device and are not stored, logged or sent anywhere.

Why add a prefix?

Prefixes like sk_live_ make keys easy to recognise in logs and let secret scanners detect leaked keys. The prefix adds no security, so the random part must still be long.