API key generator

Random API keys, secrets, and tokens — hex, base64url, or alphanumeric, generated in your browser

Generated in your browser. This page is not allowed to make network requests, so nothing you generate can leave it.

What makes an API key secure

An API key is a bearer credential: whoever holds it is you. Its only defence is being unguessable, which means at least 128 bits from a cryptographically secure random generator. Timestamps, UUIDv1s, hashes of user IDs, and Math.random() are all guessable. This page uses crypto.getRandomValues with rejection sampling, and is served with a policy that blocks every network request.

FormatBits per characterFor 128 bitsFor 256 bits
Hex432 chars64 chars
Alphanumeric~5.9522 chars43 chars
Base64url622 chars43 chars

Choosing a format

  • Alphanumeric — safe in URLs, headers, JSON, and shell commands, and selects with a double-click. A good default.
  • Hex — universal and case-insensitive; the longest for the same strength. Common for HMAC secrets and session tokens.
  • Base64url — the most compact; uses - and _ instead of + and /, and no padding, so it is safe in URLs.

Prefixes

A fixed prefix like sk_live_ or ghp_ adds no strength, but it makes a key recognizable — to a person reading a config file, and to secret scanners that search commits, logs, and pastes for leaked credentials. If you issue keys, give each kind its own prefix.

Generating keys in code

For keys your service issues, generate them server-side with a secure source:

  • Shell: openssl rand -hex 32 (256 bits)
  • Python: secrets.token_urlsafe(32)
  • Node.js: crypto.randomBytes(32).toString("base64url")
  • Elixir: :crypto.strong_rand_bytes(32) |> Base.url_encode64(padding: false)

Then store only a hash of each key (SHA-256 is fine for random 128-bit+ keys), show the key once, scope it to the least it needs, and support rotation with more than one active key at a time.

Handing a key to someone

Keys leak from where they were handed over — a Slack DM, a ticket comment, an email. Press Share it as a one-time link to send it encrypted, readable once, and gone after 24 hours. See sharing API keys and .env files securely.

Frequently asked questions

How long should an API key be?

At least 128 bits of randomness: 32 hex characters, 22 base64url characters, or 22 alphanumeric characters. The defaults here (32 alphanumeric characters, about 190 bits) leave a wide margin.

Hex, base64url, or alphanumeric?

Hex is universal and case-insensitive but needs the most characters. Base64url is the most compact and safe in URLs and headers. Alphanumeric is safe everywhere and selects with one double-click.

Is it safe to generate an API key in a browser?

Yes, when the page uses crypto.getRandomValues — the same cryptographically secure source server code uses — and cannot send the result anywhere. This page is served with a policy that blocks all network requests. For keys your service issues to its users, generate them in your backend instead.

Should API keys be hashed before they are stored?

Yes. Store a hash, show the key once, and compare hashes on each request. Because a random 128-bit key cannot be guessed, a fast hash such as SHA-256 is sufficient; slow password hashes are for low-entropy human passwords.