Token Generator
Cryptographically secure random tokens, API keys and UUIDs – generated in your browser, never sent anywhere.
Generated with crypto.getRandomValues() in your browser. Nothing is sent to a server, logged, or stored – reload the page and these are gone for good.
Random strings make useful test data alongside the phone number generator, and the url encoder makes one safe to drop into a link.
What each format is for
| Format | Alphabet | Use it for |
|---|---|---|
| Random string | Whatever you tick | Passwords, shared secrets, anything with its own character rules. |
| Hexadecimal | a–f 0–9 | Signing keys, HMAC secrets, session IDs. 64 characters is 256 bits. |
| Base64url | A–Z a–z 0–9 - _ | Anything that travels in a URL or a filename. No escaping needed. |
| API key | Base58, prefixed | Public-facing keys. Drops 0, O, I and l, so nobody mistypes one off a screen. |
| UUID v4 | Fixed | Database keys, request IDs, idempotency keys. 122 bits of randomness. |
How to generate a secure token
- Pick the format. If something else will read the token, its rules decide this – base64url for a URL, hex for a signing key, UUID for a database column. Only reach for a custom character set when nothing else applies.
- Set the length. Watch the entropy line under the buttons rather than the character count. It tells you what the token is actually worth.
- Generate. Ask for several at once if you are seeding an environment file or a set of test accounts.
- Copy it straight into where it belongs. Click a token to copy it, or download the batch as a text file. Do not paste a real secret into a chat, a ticket or a commit – that is how most of them leak.
How strong is strong enough?
Strength is not about mixing in a symbol. It is entropy: the number
of guesses an attacker has to make, expressed in bits. Each extra bit doubles that
number. The maths is length × log2(alphabet size), which is the figure
this tool shows every time it generates.
| Entropy | Verdict | Example |
|---|---|---|
| < 60 bits | Not enough for a secret | 10 lowercase characters |
| 80 bits | Fine for a session ID, thin for anything long-lived | 20 hex characters |
| 128 bits | The standard for secrets and API keys | 32 hex, or 22 base64url characters |
| 256 bits | Beyond anything brute force can reach | 64 hex characters |
This is why the old "weak / medium / strong" labels mislead: a 40-character lowercase token carries about 188 bits and is far stronger than a 12-character one full of symbols, which carries 78. Length beats character variety, every time.
Why the random source matters more than the length
Most browser token generators build their output with
Math.random(). It is fast and it looks random, but it is a plain
pseudo-random generator: its internal state can be recovered from a short run of
outputs, after which every value it will ever produce is predictable. A 256-bit token
from a predictable source is worth nothing at all.
This tool uses crypto.getRandomValues(), the browser's cryptographically
secure generator, seeded by the operating system. It also uses
rejection sampling rather than the usual byte % length:
256 is not a multiple of 62, so a plain modulo makes the first few characters of an
alphabet about 1.3 times more likely than the rest. Bytes that would skew the result
are discarded and redrawn.
Frequently asked questions
crypto.getRandomValues(), the same
cryptographically secure source your operating system provides, with the
modulo bias removed. At 128 bits or more they are suitable for API keys,
signing secrets and session identifiers.
sk_live_ so a leaked key can be recognised and revoked
without anyone having to identify it by eye.
Need other placeholder data? The phone number generator makes numbers that reach nobody, and the username generator fills in the rest of a test account.