API key generator. Generate cryptographically secure API keys in hex, base64, alphanumeric, and UUID v4 formats.
100% browser-based — your data never leaves your device
Generate cryptographically secure API keys in hex, base64, alphanumeric, and UUID formats.
e2b072ecaaf3527e050346c108c48ede762047544e462bd2e0b820bd875c8f9bb0e167e55d7a76a26d88b5c16db63604e1e2b64d1146e174756741396c3eb5698fb85af94158159a358fe77e13f99744Decode and inspect JWT tokens instantly.
Password GeneratorGenerate strong, secure random passwords with customizable options.
Passphrase GeneratorGenerate memorable, secure passphrases from word lists.
UUID GeneratorGenerate UUID v4 identifiers instantly.
UUID ValidatorValidate UUID strings and identify the version (v1, v2, v3, v4, v5).
Hash GeneratorGenerate SHA-1, SHA-256, SHA-384, and SHA-512 hashes from text.
JWT GeneratorGenerate signed JWT tokens for testing with custom headers and payloads.
Bcrypt Hash GeneratorGenerate bcrypt password hashes with configurable salt rounds.
API Key GeneratorGenerate cryptographically secure API keys in hex, base64, alphanumeric, and UUID formats.
HMAC GeneratorGenerate HMAC hashes with SHA-256, SHA-384, and SHA-512 algorithms.
AES EncryptEncrypt and decrypt text using AES-256-GCM with a password-based key.
Generating a good API key is about getting both entropy and format right. This tool draws on crypto.getRandomValues() for operating-system-grade randomness and lets you shape the output for whatever system will consume it.
Every web service that authenticates machine-to-machine traffic needs keys, and the boring reality is that most teams generate them once and never think again. This tool makes that first step painless. The hex format matches what providers like GitHub and GitLab use, base64 gives you a more compact string, alphanumeric is friendlier for humans to handle, and UUID v4 is the standard for resource identifiers in distributed systems.
Bulk generation is the feature that saves real time during onboarding, rotation, and infrastructure changes, when you suddenly need fresh keys for a dozen services. Producing up to fifty at once with entropy displayed for each format means you can mint a complete set of replacement keys, then rotate them in one pass.
An API key is a credential that grants access to your systems and your provider accounts. Generating it in a tool that uploads it means the key now exists in two places, yours and theirs, plus every hop in between, doubling the chances it leaks before it is even deployed.
Here the key is born, displayed, and copied entirely on your device. No server sees the output, no logs record it, and the key's only existence outside your browser is the one you choose to save in your environment or secrets manager.
Select hex, base64, alphanumeric, or UUID v4 as your key format.
Adjust the key length (16-128 characters) using the slider.
Click Generate to produce secure keys. Copy individual keys or all at once.
Practical examples to help you get the most out of API Key Generator:
// Format: Hex // Length: 32 // Result: a1b2c3d4e5f6789012345678abcdef0123456789abcdef0123456789abcdef
// Format: Base64 // Length: 32 // Result: dGhpcyBpcyBhIHNhbXBsZSBiYXNlNjQgYXBpIGtleQ==
Never use Math.random() for generating API keys — it's not cryptographically secure. This tool uses crypto.getRandomValues() for true randomness.
Never commit API keys to Git. Use environment variables or a secrets manager. If a key is leaked, revoke it immediately and generate a new one.
Hex is most compatible (e.g., GitHub uses hex). Base64 is more compact. UUID v4 is standard for resource identifiers. Alphanumeric is human-friendly.
128 bits (32 hex chars) is sufficient for most APIs. For highly sensitive systems, use 256 bits (64 hex chars).
Yes. The tool uses window.crypto.getRandomValues(), which is cryptographically secure and backed by the operating system's entropy sources.
Generate keys in hex, base64, alphanumeric random strings, or UUID v4 format.
All keys are generated using crypto.getRandomValues() for true cryptographic randomness.
Adjust key length from 16 to 128 characters with a simple slider control.
Generate up to 50 keys at once with entropy information for each format.
API Key Generator is useful in a variety of scenarios across different workflows:
Generating API keys for web service authentication
Creating secure tokens for application secrets and encryption keys
Producing UUID-based identifiers for distributed systems
Hex keys are most compatible (used by GitHub and GitLab). Base64 is more compact. UUID v4 is standard for resource IDs. Alphanumeric is human-friendly.
Generate new API keys periodically and deprecate old ones. Use the bulk generation feature to create replacement keys for multiple services at once.
Explore more tools in the Security workspace:
JWT Decoder
Decode and inspect JWT tokens instantly.
Password Generator
Generate strong, secure random passwords with customizable options.
Passphrase Generator
Generate memorable, secure passphrases from word lists.
UUID Generator
Generate UUID v4 identifiers instantly.
UUID Validator
Validate UUID strings and identify the version (v1, v2, v3, v4, v5).
Hash Generator
Generate SHA-1, SHA-256, SHA-384, and SHA-512 hashes from text.