AnkhKit

Secure Token Generator (Hex & Base64) — Free

Runs 100% in your browser — your files never leave your device.

Session keys, API secrets, CSRF tokens, invite codes — anything security-sensitive needs real randomness, not Math.random(). This generator uses your browser's WebCrypto API and can emit hex or URL-safe base64. Choose the byte length — the matching bit count of entropy is shown right beside the controls.

How it works

  1. 1

    Choose the length

    Bytes of entropy, from 1 to 1024 — 32 bytes (256 bits) is the default.

  2. 2

    Pick the encoding

    Hexadecimal for keys and secrets, URL-safe base64 for tokens in links.

  3. 3

    Generate and copy

    Each click draws fresh randomness from WebCrypto; nothing is stored or sent.

About this tool

What makes a token a token

A token here means a cryptographically random identifier with no meaning beyond itself — generated from your browser's cryptographic randomness, not from a counter or a dictionary. API keys, session identifiers, bearer secrets, webhook verification values: all are tokens in this sense.

Entropy is the whole security model

A token resists guessing exactly as hard as its entropy allows: 128 bits of randomness is unguessable in any practical universe, and the tool generates at that class by default. The threat is never the algorithm — it is tokens that are shorter, logged, or reused.

Handle tokens like secrets

A token pasted into a chat, committed to a repository, or logged in a URL is burned — rotate it. Generate locally (this tool computes in your browser), transmit over HTTPS, store hashed where possible.

Frequently asked questions

How long should my token be?

128 bits of entropy — 22-ish base64 characters or 32 hex characters — is the practical standard for anything security-relevant. Longer is fine; shorter starts costing margin.

Is the token generated securely?

Yes — the tool draws from your browser's cryptographic random source, locally, and the value is never transmitted or stored.

Can I use a generated token as an API key?

Yes — a high-entropy random string is exactly what API keys are. Store it, require it on requests, and treat its exposure as a rotation event.

More generators