About GenerateKey
What this site is, who made it, and how to check it does what it claims.
What it is
GenerateKey is a set of generators for the random values developers actually need — passwords, Diceware passphrases, UUIDs, hex and base64 secrets, JWT and framework secrets, SSH and WireGuard keys, and more. Every one runs entirely in your browser through the Web Crypto API (crypto.getRandomValues and crypto.subtle). There is no server-side generation, no account, no cookie, no ad, and nothing that records a generated value. No analytics or third-party scripts are loaded. Copying a value sends it to your system clipboard; your device may sync that clipboard with other devices.
How to check local generation
Load a generator, disconnect from the network and press Generate again. It continues to work because generation is local. Offline operation alone does not prove a site is trustworthy: inspect the delivered code and network requests too. For the thorough version, open your browser's Network tab and press generate: you will see no request at all. And you can read the exact JavaScript this page runs — it is served unminified, and it is the entire program. This is the same argument spelled out on is it safe to use an online password generator.
What we actually checked
The repository includes browser tests for output formats, clipboard behavior, generator controls and mobile layouts, plus checks for static HTML metadata and links. These checks help catch regressions; they are not an independent cryptographic audit. Inspect the implementation and use your platform’s trusted local tooling for high-value production keys.
Security limits
Client-side generation moves the trust question, it does not remove it. You are trusting that the code served to you does what it claims, and the page is re-fetched on every visit — so a malicious operator, or anyone who compromises the DNS or CDN, could serve different code tomorrow. That is why a secret protecting something irreplaceable should be generated with a tool you installed, why the SSH page tells you to prefer ssh-keygen for a production key, and why this site will never publish a crypto-wallet seed-phrase generator. The threat model scales with the value of the secret, and we would rather say so than pretend otherwise.
Who made it, and how to reach us
Built by maxbook. If you find a security or correctness problem, email max@maxken.fr — there is a security.txt with the same contact.
How generation works
About & privacyGenerated on your device
Web Crypto provides the randomness. Generation works offline after the page has loaded.
No tracking or saved values
No analytics scripts, accounts, cookies or local storage. Values stay in this tab until you copy them.
Browser and device security
A compromised browser or device can expose values. For production private keys, use a trusted local tool.
All generators
- Base64 Secret Generator
- UUID Generator
- Password Generator
- Hex Secret Generator
- JWT Secret Generator
- Passphrase Generator
- SSH Key Generator (Ed25519)
- PIN Generator
- WireGuard Key Generator
- API Key Generator
- TOTP Secret Generator
- Django SECRET_KEY Generator
- Laravel APP_KEY Generator
- NextAuth Secret Generator
- Flask SECRET_KEY Generator
- Rails secret_key_base Generator
- Strapi APP_KEYS Generator
- ULID Generator
- Nano ID Generator
- Symfony APP_SECRET Generator
- VAPID Key Generator
Guides
Browse guides ↗openssl rand, explained
What the command actually produces, and how to get the same bytes without it.
Read guideHow long should a JWT secret be?
Minimum key sizes for HMAC signing, and how to encode and store them.
Read guideEd25519 vs RSA for SSH keys
Ed25519 is a convenient modern default. Compatibility and your security policy decide the exceptions.
Read guideAre online password generators safe?
Local generation helps. Trust in the code, your browser and your device still matters.
Read guideHow to generate a random string
The right call in eight languages, and the popular ones that quietly aren't random.
Read guideApplication secrets by framework
Variable names, formats and local commands in one place.
Read guideUUID v4 vs v7
Random identifiers or time-ordered IDs, with the trade-offs explained.
Read guide