Skip to content
M2TOOLKIT

Security · free tool

Random Token & API Key Generator

Generate secure random strings for API keys, secrets, session tokens and test data.

Use it as often as you like — it's free, with no sign-up and no limits.

  • Security
  • Free
  • No sign-up
  • Runs in your browser
  • Updated
Format
32

128 bits or more is recommended for API keys and session secrets. All values come from crypto.getRandomValues.

Everything you type is processed in your browser. Nothing you enter is sent to our servers or stored by us.

How to use the Random Token Generator

  1. Choose a format and length.
  2. Choose how many tokens.
  3. Copy or download them.

What does this tool do?

Tokens are built from crypto.getRandomValues. Base64URL and hex formats are generated from random bytes, so 32 bytes always means 256 bits of randomness. Character-set formats use unbiased selection from the alphabet you choose.

Why use it?

  • Secrets for JWT signing, webhooks and sessions.
  • Invite codes with unambiguous characters.
  • Bulk test data.

How long should a secret be?

128 bits (16 bytes) is the practical minimum for secrets; 256 bits (32 bytes) is common for signing keys.

Privacy

Everything you type is processed in your browser. Nothing you enter is sent to our servers or stored by us. There's no account to create and nothing to install.

Frequently asked questions

Is it safe to do this in a browser?

Yes, because nothing leaves your device. Everything is generated or checked with your browser's built-in cryptography (the Web Crypto API) — no network requests are made with what you type.

How long should an API key or secret be?

At least 128 bits of randomness, and 256 bits is a common choice. 32 random bytes gives 256 bits, which is 64 hex characters or 43 Base64URL characters.

Last reviewed by the M2Toolkit team.

Other tools people use alongside the random token generator.