API key generator
Random API keys, secrets, and tokens — hex, base64url, or alphanumeric, generated in your browser
Your browser blocked the hand-off. Copy the API key, then paste it at oncepad.com.
Generated in your browser. This page is not allowed to make network requests, so nothing you generate can leave it.
What makes an API key secure
An API key is a bearer credential: whoever holds it is you. Its only defence is being unguessable, which means at least 128 bits from a cryptographically secure random generator. Timestamps, UUIDv1s, hashes of user IDs, and Math.random() are all guessable. This page uses crypto.getRandomValues with rejection sampling, and is served with a policy that blocks every network request.
| Format | Bits per character | For 128 bits | For 256 bits |
|---|---|---|---|
| Hex | 4 | 32 chars | 64 chars |
| Alphanumeric | ~5.95 | 22 chars | 43 chars |
| Base64url | 6 | 22 chars | 43 chars |
Choosing a format
- Alphanumeric — safe in URLs, headers, JSON, and shell commands, and selects with a double-click. A good default.
- Hex — universal and case-insensitive; the longest for the same strength. Common for HMAC secrets and session tokens.
- Base64url — the most compact; uses
-and_instead of+and/, and no padding, so it is safe in URLs.
Prefixes
A fixed prefix like sk_live_ or ghp_ adds no strength, but it makes a key recognizable — to a person reading a config file, and to secret scanners that search commits, logs, and pastes for leaked credentials. If you issue keys, give each kind its own prefix.
Generating keys in code
For keys your service issues, generate them server-side with a secure source:
- Shell:
openssl rand -hex 32(256 bits) - Python:
secrets.token_urlsafe(32) - Node.js:
crypto.randomBytes(32).toString("base64url") - Elixir:
:crypto.strong_rand_bytes(32) |> Base.url_encode64(padding: false)
Then store only a hash of each key (SHA-256 is fine for random 128-bit+ keys), show the key once, scope it to the least it needs, and support rotation with more than one active key at a time.
Handing a key to someone
Keys leak from where they were handed over — a Slack DM, a ticket comment, an email. Press Share it as a one-time link to send it encrypted, readable once, and gone after 24 hours. See sharing API keys and .env files securely.
Frequently asked questions
How long should an API key be?
At least 128 bits of randomness: 32 hex characters, 22 base64url characters, or 22 alphanumeric characters. The defaults here (32 alphanumeric characters, about 190 bits) leave a wide margin.
Hex, base64url, or alphanumeric?
Hex is universal and case-insensitive but needs the most characters. Base64url is the most compact and safe in URLs and headers. Alphanumeric is safe everywhere and selects with one double-click.
Is it safe to generate an API key in a browser?
Yes, when the page uses crypto.getRandomValues — the same cryptographically secure source server code uses — and cannot send the result anywhere. This page is served with a policy that blocks all network requests. For keys your service issues to its users, generate them in your backend instead.
Should API keys be hashed before they are stored?
Yes. Store a hash, show the key once, and compare hashes on each request. Because a random 128-bit key cannot be guessed, a fast hash such as SHA-256 is sufficient; slow password hashes are for low-entropy human passwords.