Generate keys and passwords

Random values, generated locally in your browser.

Hex secret generator

Usage

Random bytes encoded as hexadecimal.

All generators

Which format
do I need?

Choose the format your application expects.

Choose a generator by purpose
You need to…Start withWhy it fits
Protect an accountPassword ↗Random characters
Configure an appHex secret ↗32 bytes · 256 bits
Sign a JWTJWT secret ↗HS256 or HS512
Identify a recordUUID ↗v4 random · v7 time-ordered
Remember a secretPassphrase ↗Random, readable words

How generation works

About & privacy

Generated on your device

Web Crypto provides the randomness. Generation works offline after the page has loaded.

No tracking or saved values

No analytics scripts, accounts, cookies or local storage. Values stay in this tab until you copy them.

Browser and device security

A compromised browser or device can expose values. For production private keys, use a trusted local tool.

FAQ

Which generator should I use?

Use a password for an account, a passphrase for a secret you must remember, and a UUID for a record identifier. For an application secret, choose the tool for your framework or generate 32 random bytes in hex or base64. Follow the receiving application's format requirements.

Are my generated keys sent to a server?

No. Generation runs in this tab using the Web Crypto API. This site does not send or save generated values and loads no analytics scripts. Copying transfers a value to your system clipboard, which may be accessible to other apps or clipboard sync.

Can I use an online generator for production secrets?

You must trust the code delivered to your browser and the device running it. Client-side generation reduces exposure but is not a security audit. For long-lived production keys, use a trusted local command or your platform's secret manager. Each relevant tool includes a local alternative.

Does a longer encoded key mean more security?

Not necessarily. 32 random bytes have 256 bits of entropy whether written as 64 hex characters, 44 padded base64 characters or 43 unpadded base64url characters. Encoding changes the representation, not the underlying randomness.