Generate keys and passwords
Random values, generated locally in your browser.
Hex secret generator
UsageRandom bytes encoded as hexadecimal.
All generators
Hex secret
Random bytes encoded as hexadecimal.
Base64 secret
Standard base64 or URL-safe base64url.
JWT secret
Signing keys for HS256, HS384 and HS512.
API key
Random keys with a custom prefix.
SSH key
An Ed25519 key pair in OpenSSH format.
WireGuard
A key pair and optional preshared key.
TOTP secret
Base32 secrets and authenticator setup URIs.
VAPID keys
A public and private key pair for Web Push.
Password
Choose the length and character sets.
Passphrase
Random words from the EFF wordlist.
PIN
Random digits with a choice of length.
UUID
Random v4 or time-ordered v7 identifiers.
ULID
Sortable identifiers with a timestamp.
Nano ID
Compact, URL-safe random identifiers.
Auth.js / NextAuth
A 32-byte secret for AUTH_SECRET.
Django
A 50-character SECRET_KEY.
Laravel
An APP_KEY for your chosen cipher.
Flask
A 64-character hexadecimal SECRET_KEY.
Rails
A 64-byte hex secret_key_base.
Strapi
APP_KEYS and secrets in an .env block.
Symfony
A random APP_SECRET for your application.
No tools found. Try “JWT”, “password” or “Django”.
Which format
do I need?
Choose the format your application expects.
| You need to… | Start with | Why it fits |
|---|---|---|
| Protect an account | Password ↗ | Random characters |
| Configure an app | Hex secret ↗ | 32 bytes · 256 bits |
| Sign a JWT | JWT secret ↗ | HS256 or HS512 |
| Identify a record | UUID ↗ | v4 random · v7 time-ordered |
| Remember a secret | Passphrase ↗ | Random, readable words |
How generation works
About & privacyGenerated on your device
Web Crypto provides the randomness. Generation works offline after the page has loaded.
No tracking or saved values
No analytics scripts, accounts, cookies or local storage. Values stay in this tab until you copy them.
Browser and device security
A compromised browser or device can expose values. For production private keys, use a trusted local tool.
Guides
Browse guides ↗openssl rand, explained
What the command actually produces, and how to get the same bytes without it.
Read guideHow long should a JWT secret be?
Minimum key sizes for HMAC signing, and how to encode and store them.
Read guideEd25519 vs RSA for SSH keys
Ed25519 is a convenient modern default. Compatibility and your security policy decide the exceptions.
Read guideAre online password generators safe?
Local generation helps. Trust in the code, your browser and your device still matters.
Read guideHow to generate a random string
The right call in eight languages, and the popular ones that quietly aren't random.
Read guideApplication secrets by framework
Variable names, formats and local commands in one place.
Read guideUUID v4 vs v7
Random identifiers or time-ordered IDs, with the trade-offs explained.
Read guideFAQ
Which generator should I use?
Use a password for an account, a passphrase for a secret you must remember, and a UUID for a record identifier. For an application secret, choose the tool for your framework or generate 32 random bytes in hex or base64. Follow the receiving application's format requirements.
Are my generated keys sent to a server?
No. Generation runs in this tab using the Web Crypto API. This site does not send or save generated values and loads no analytics scripts. Copying transfers a value to your system clipboard, which may be accessible to other apps or clipboard sync.
Can I use an online generator for production secrets?
You must trust the code delivered to your browser and the device running it. Client-side generation reduces exposure but is not a security audit. For long-lived production keys, use a trusted local command or your platform's secret manager. Each relevant tool includes a local alternative.
Does a longer encoded key mean more security?
Not necessarily. 32 random bytes have 256 bits of entropy whether written as 64 hex characters, 44 padded base64 characters or 43 unpadded base64url characters. Encoding changes the representation, not the underlying randomness.