About GenerateKey

What this site is, who made it, and how to check it does what it claims.

What it is

GenerateKey is a set of generators for the random values developers actually need — passwords, Diceware passphrases, UUIDs, hex and base64 secrets, JWT and framework secrets, SSH and WireGuard keys, and more. Every one runs entirely in your browser through the Web Crypto API (crypto.getRandomValues and crypto.subtle). There is no server-side generation, no account, no cookie, no ad, and nothing that records a generated value. No analytics or third-party scripts are loaded. Copying a value sends it to your system clipboard; your device may sync that clipboard with other devices.

How to check local generation

Load a generator, disconnect from the network and press Generate again. It continues to work because generation is local. Offline operation alone does not prove a site is trustworthy: inspect the delivered code and network requests too. For the thorough version, open your browser's Network tab and press generate: you will see no request at all. And you can read the exact JavaScript this page runs — it is served unminified, and it is the entire program. This is the same argument spelled out on is it safe to use an online password generator.

What we actually checked

The repository includes browser tests for output formats, clipboard behavior, generator controls and mobile layouts, plus checks for static HTML metadata and links. These checks help catch regressions; they are not an independent cryptographic audit. Inspect the implementation and use your platform’s trusted local tooling for high-value production keys.

Security limits

Client-side generation moves the trust question, it does not remove it. You are trusting that the code served to you does what it claims, and the page is re-fetched on every visit — so a malicious operator, or anyone who compromises the DNS or CDN, could serve different code tomorrow. That is why a secret protecting something irreplaceable should be generated with a tool you installed, why the SSH page tells you to prefer ssh-keygen for a production key, and why this site will never publish a crypto-wallet seed-phrase generator. The threat model scales with the value of the secret, and we would rather say so than pretend otherwise.

Who made it, and how to reach us

Built by maxbook. If you find a security or correctness problem, email max@maxken.fr — there is a security.txt with the same contact.

How generation works

About & privacy

Generated on your device

Web Crypto provides the randomness. Generation works offline after the page has loaded.

No tracking or saved values

No analytics scripts, accounts, cookies or local storage. Values stay in this tab until you copy them.

Browser and device security

A compromised browser or device can expose values. For production private keys, use a trusted local tool.

All generators