Choose a length and encoding below and generate a secure token. Everything runs in your browser using a cryptographically secure random source — nothing is sent to our server, and nothing generated here is stored.
Generated locally in your browser using a cryptographically secure random source — nothing is sent to our server, and nothing generated here is stored.
Computed entirely in your browser — nothing you enter here is sent to our server.
Generating…
How This Tool Works
This tool draws raw random bytes directly from crypto.getRandomValues() — the same cryptographically secure source browsers use for security-critical randomness — and encodes them as either hex (each byte becomes 2 hex characters) or base64url (URL-safe base64, no padding). This is the standard shape for an API key, session token, or CSRF token, as opposed to a human-typed character set. 32 bytes (256 bits) is a common, generous default for API keys.
FAQ
Is my data uploaded anywhere?
No. The token is generated entirely in your browser and never sent to our server or stored anywhere.
Hex or base64url — which should I choose?
Base64url is more compact (about 33% shorter for the same number of random bytes) and safe to use directly in URLs; hex is simpler and universally supported. Use whichever your target system expects.
How many bytes should I use?
16 bytes (128 bits) is generally considered a safe minimum for session tokens; 32 bytes (256 bits) is a common, more generous choice for API keys and long-lived secrets.