Random Base64 Secret Generator

Random secrets encoded as base64 or URL-safe base64url.

Copy the result before closing this tab.

32 random bytes become 43 unpadded base64url characters or 44 padded base64 characters. Choose the encoding your application expects; both represent the same amount of randomness.

Base64 vs base64url

Base64 packs 6 bits into each character, making it ~33% denser than hex: 32 random bytes fit in 43 characters instead of 64. Standard base64 uses + and / plus = padding — characters that break URLs, filenames and some config parsers. base64url (RFC 4648 §5) swaps them for - and _ and drops the padding, which is why it's the default here and the encoding JWTs themselves use.

Where you'd use one

Random base64 strings are the conventional format for many framework secrets: a NextAuth/Auth.js AUTH_SECRET, cookie-session keys, Laravel's APP_KEY (base64-prefixed), or any place documentation says openssl rand -base64 32. This page generates the same thing — 16 to 128 bytes from your browser's CSPRNG, encoded in the variant you pick.

Entropy comes from bytes, not characters

A secret's strength is the number of random bytes behind it, not its printed length. 32 bytes carry 256 bits of entropy whether shown as 64 hex characters or 43 base64 characters. Everything is generated locally with crypto.getRandomValues(); nothing is transmitted or stored.

FAQ

base64 or base64url?

base64url unless something demands otherwise. Standard base64 uses + and / plus = padding — characters that break URLs, filenames and some config parsers. base64url (RFC 4648 §5) swaps them for - and _ and drops the padding. One important exception: framework secrets like Laravel’s APP_KEY expect standard base64. A mismatched decoder may reject or mishandle the URL-safe variant; follow the receiving application’s documentation.

Is this the same as openssl rand -base64 32?

Yes, if you pick standard base64 — same 32 random bytes, same encoding. Note that the 32 in that command is the number of bytes, not the length of the output: it prints 44 characters (43 plus one = of padding).

Why is 32 bytes only 43 characters?

base64 packs 6 bits into each character, so 32 bytes (256 bits) needs ⌈256/6⌉ = 43 characters — about 33% denser than hex's 64. Both carry exactly the same 256 bits of entropy. A secret's strength is the number of random bytes behind it, never its printed length.

How generation works

About & privacy

Generated on your device

Web Crypto provides the randomness. Generation works offline after the page has loaded.

No tracking or saved values

No analytics scripts, accounts, cookies or local storage. Values stay in this tab until you copy them.

Browser and device security

A compromised browser or device can expose values. For production private keys, use a trusted local tool.

Other generators

All generators ↗