Secure Token Generator (Hex & Base64) — Free
Runs 100% in your browser — your files never leave your device.
Session keys, API secrets, CSRF tokens, invite codes — anything security-sensitive needs real randomness, not Math.random(). This generator uses your browser's WebCrypto API and can emit hex or URL-safe base64. Choose the byte length — the matching bit count of entropy is shown right beside the controls.
How it works
- 1
Choose the length
Bytes of entropy, from 1 to 1024 — 32 bytes (256 bits) is the default.
- 2
Pick the encoding
Hexadecimal for keys and secrets, URL-safe base64 for tokens in links.
- 3
Generate and copy
Each click draws fresh randomness from WebCrypto; nothing is stored or sent.
About this tool
What makes a token a token
A token here means a cryptographically random identifier with no meaning beyond itself — generated from your browser's cryptographic randomness, not from a counter or a dictionary. API keys, session identifiers, bearer secrets, webhook verification values: all are tokens in this sense.
Entropy is the whole security model
A token resists guessing exactly as hard as its entropy allows: 128 bits of randomness is unguessable in any practical universe, and the tool generates at that class by default. The threat is never the algorithm — it is tokens that are shorter, logged, or reused.
Handle tokens like secrets
A token pasted into a chat, committed to a repository, or logged in a URL is burned — rotate it. Generate locally (this tool computes in your browser), transmit over HTTPS, store hashed where possible.
Frequently asked questions
How long should my token be?
128 bits of entropy — 22-ish base64 characters or 32 hex characters — is the practical standard for anything security-relevant. Longer is fine; shorter starts costing margin.
Is the token generated securely?
Yes — the tool draws from your browser's cryptographic random source, locally, and the value is never transmitted or stored.
Can I use a generated token as an API key?
Yes — a high-entropy random string is exactly what API keys are. Store it, require it on requests, and treat its exposure as a rotation event.