Each key is drawn with the Web Crypto API (crypto.getRandomValues), a CSPRNG. Generation stays in your browser. EverydayTools never receives the secret. Store it in env or a secrets manager—not git.

Skip to API key generator

API Key Generator

Generate a cryptographically secure API key or webhook secret in your browser. Pick hex, Base64url, or alphanumeric, add an optional prefix, and copy once. For your own APIs—not a Stripe, OpenAI, or GitHub account key.

By Muhammad Abdullah Rauf · Founder, EverydayTools.proUpdated 2026-09-14· Reviewed by EverydayTools Editorial Team

What is an API key generator?

An API key generator creates a long, random secret used to authenticate software—not a person. A secure one uses a CSPRNG such as crypto.getRandomValues, not Math.random(), and lets you choose hex, Base64url, or alphanumeric output.

US developers usually want one of two things when they search “API key generator.” Either they need a random secret for their own API (X-API-Key, a webhook HMAC secret, a local .env value), or they need a key from a vendor dashboard (Stripe, OpenAI, Google Cloud). This page does the first job only.

The generator runs in your browser with Web Crypto. You pick a format, set body length, optionally add a prefix such as sk_test_ or whsec_, then copy the result. EverydayTools never sees the key.

  • CSPRNG entropy from the OS via crypto.getRandomValues
  • Hex, Base64url, alphanumeric, or classic Base64
  • Optional prefixes so secret scanners can spot leaks
  • Live entropy so you can hit a 128-bit or 256-bit floor

Generate ≥128 bits of CSPRNG material, label live vs test with a prefix, show the raw key once, and keep it out of git and frontend bundles.

Quick answers

Concise answers for common searches — definitions, steps, and comparisons.

How do I generate an API key online for free?

Open this generator, choose hex, Base64url, or alphanumeric, set length, click Generate, then copy. No signup—the key stays in your browser. This does not issue vendor account keys.

What makes an API key secure?

Enough CSPRNG entropy (≥128 bits), no predictable generator, private storage, and rotation after a leak. This tool supplies the random material via Web Crypto.

Does this API key generator upload keys?

No. crypto.getRandomValues runs locally. EverydayTools does not receive the generated secret.

How to generate a secure API key

  1. Choose a format

    Hex for headers and databases, Base64url for compact URL-safe tokens, alphanumeric for developer-facing keys, or classic Base64 when a stack already expects +/.

  2. Set body length

    Use at least 32 hex characters (128 bits) for typical API keys. Prefer 64 hex or 43 Base64url characters (~256 bits) for webhook signing secrets.

  3. Optional prefix

    Add sk_test_, sk_live_, or whsec_ so logs and GitHub secret scanning can recognize a leak. The random body still carries the entropy.

  4. Generate, copy, store

    Generate, copy once (or copy as a .env line), then paste into a secrets manager or environment variable. Do not commit the value.

API key security

Never commit secrets to git

Put keys in environment variables or a secrets manager. Add .env to .gitignore. If a key hits a public repo, rotate it immediately.

Keep secret keys off the frontend

Browser bundles, mobile apps, and public repos can be extracted. Only publish identifiers that are designed to be public.

Show a customer key once, store a hash

When you issue keys in your own product, display the plaintext at creation, persist a SHA-256 (or stronger) hash, and compare hashes on each request.

Rotate after a leak—and on a schedule for high-value secrets

Treat a leaked prefix in logs the same as a leak. Keep a dual-key window so old and new secrets both work while clients update.

Prefer 256 bits for webhook HMAC secrets

Signing secrets are long-lived and high impact. 64 hex characters or 43 Base64url characters is cheap insurance.

How this secure API key generator works

Each body character is sampled with crypto.getRandomValues and rejection sampling so every alphabet symbol is equally likely. Prefix and suffix are concatenated after sampling and are not counted as entropy. No key material is sent to EverydayTools.

Formula

Entropy_bits = body_length × log2(alphabet_size)
Hex = 4 bits/char · Base64url = 6 bits/char · Alphanumeric ≈ 5.95 bits/char
Target ≥ 128 bits for typical API keys; ≥ 256 bits for long-lived signing secrets

Assumptions

  • A modern browser with the Web Crypto API
  • Uniform CSPRNG bytes from the operating-system entropy pool
  • Prefix and suffix are identifiers, not secret entropy

Limitations

  • Does not mint OAuth access tokens or signed JWTs
  • Does not replace a password generator for human logins
  • Does not store, rotate, or revoke keys inside your product
  • Does not issue vendor account keys (Stripe, OpenAI, Google, AWS)

Sources

API Key Generator examples

Hex API key (128-bit class)

Input

Format: Hex · Length: 32 · Prefix: none

Output

a3f82c1d4e7b09534c0e11f2b8d63a90

32 hex characters = 128 bits. A solid default for generate-api-key-online workflows.

Prefixed alphanumeric secret

Input

Format: Alphanumeric · Length: 32 · Prefix: sk_test_

Output

sk_test_Kx3fW9AbcRq7mZnP2vLdTj8YhQ5sNu

Looks like a Stripe-style test key so scanners can find it. It is not a Stripe-issued credential.

Webhook-style secret

Input

Format: Hex · Length: 64 · Prefix: whsec_

Output

whsec_ + 64 hex characters

256-bit-class body for HMAC webhook secrets you store in WEBHOOK_SECRET.

API key formats at a glance

Encoding is a transport choice. Entropy is alphabet size times body length—not how fancy the string looks.

FormatAlphabet~128-bit lengthURL-friendlyTypical use
Hex0–9 a–f32 charsYesHeaders, databases, webhook bodies
Base64urlA–Z a–z 0–9 - _22 charsYesCompact tokens in URLs
AlphanumericA–Z a–z 0–922 charsYesPrefixed developer keys
Base64A–Z a–z 0–9 + /22 charsNeeds careLegacy stacks that expect +/

API Key Generator vs related EverydayTools

Use the page that matches the job so search intent stays clean.

NeedUse this pageUse instead
Random API key or webhook secretYes—
Human login passwordNoPassword Generator
RFC UUID / GUID identifierNoUUID Generator
Signed JWT access tokenNoJWT Generator
Generic bulk random stringsOptionalRandom String Generator
Stripe / OpenAI / GitHub account keyNoThat vendor’s dashboard

When to use this API key generator

API builders

Opaque API authentication keys

Mint X-API-Key or shared-secret Bearer values for your own REST services and internal gateways.

Integrations

Webhook signing secrets

Create high-entropy secrets (often prefixed whsec_) for HMAC verification. This page creates the shared secret; your app still computes the signature.

Local development

Dev and staging credentials

Generate separate test keys per environment so you can rotate staging without touching production.

Fixtures

Bulk keys for seed data

Create up to 25 keys at once for multi-tenant fixtures or local mocks. Download or copy them as .env lines.

When to use API Key Generator vs related tools

API keys are opaque secrets. UUIDs are identifiers. JWTs are signed statements. Vendor API keys are issued by that vendor.

Related toolUse this tool whenUse related tool when
UUID GeneratorYou need an authentication secret or webhook signing secret.You need RFC UUID v1/v4/v7 identifiers for databases, events, or records.
JWT GeneratorYou need an opaque shared secret string.You need a signed JWT with claims (iss, exp, sub) for bearer auth.

Common mistakes to avoid

Using Math.random() for production API keys

Use crypto.getRandomValues here, or crypto.randomBytes / secrets on the server.

Treating a short key as secure enough

Check bits, not vibes. Stay at or above 128 bits; use 256 bits for signing secrets.

Confusing this tool with a vendor dashboard

To call Stripe, OpenAI, or Google APIs you still create a key in that product. This page only mints random secrets you control.

When this tool isn't the right choice

You need a memorable human password

Use a password generator. API keys should be long and unmemorable on purpose.

You need a signed JWT

Opaque keys are not JWTs. Use the JWT Generator for claim-bearing tokens.

You need an RFC UUID as a record ID

Use the UUID Generator. A UUID can be an opaque ID; this page is for auth secrets.

You need a Stripe, OpenAI, Google, or GitHub account key

Sign in to that vendor and create the key there. A random string from this page will not authenticate their API.

What to do next

Continue the workflow with the right follow-up tool.

Advertisement

Frequently asked questions

Does this create a Stripe, OpenAI, or GitHub API key?

No. Account keys come from that vendor’s dashboard after you sign in. This tool only creates a random secret for your own app, mocks, or webhook HMAC. Style presets such as sk_test_ copy a common prefix so scanners can recognize leaks—they are not Stripe or GitHub credentials.

How do I generate a secure API key?

Use a CSPRNG, not Math.random(). On this page, pick a format, set a body length that reaches at least 128 bits (32 hex or about 22 Base64url characters), optionally add a prefix, then generate and copy. The key is created with crypto.getRandomValues in your browser.

Are API keys generated here uploaded or stored?

No. Generation is client-side only. EverydayTools does not receive, log, or save your keys. A share link copies options (format, length, prefix)—never the secret. Confirm in the browser Network tab while you generate.

How long should an API key be?

Aim for at least 128 bits of entropy: 32 hex characters, about 22 Base64url characters, or about 22 alphanumeric characters. Use 64 hex or 43 Base64url characters (~256 bits) for long-lived webhook or master secrets.

Should I use hex, Base64url, or alphanumeric?

All are fine with a CSPRNG. Hex is safest in URLs and headers. Base64url is denser and URL-safe. Alphanumeric is common for developer-facing keys with prefixes. Classic Base64 is denser too but +/ often needs encoding in URLs.

What is the difference between an API key, an API token, and a JWT?

An API key is usually a long-lived opaque secret. “Token” may mean the same thing or a short-lived OAuth credential. A JWT is a signed statement with claims (iss, exp, sub). This page generates opaque random secrets—not signed JWTs.

Should I add a prefix like sk_live_ or whsec_?

Yes for operations. Distinctive prefixes help humans and secret scanners notice a leak in git or logs. They do not replace entropy in the random body and they do not turn the string into a vendor-issued key.

Is a browser API key generator safe?

Yes when it uses Web Crypto (crypto.getRandomValues) and does not transmit the key. Avoid any generator that still uses Math.random() for production secrets. Your storage, rotation, and access control still matter after you copy the value.

Where should I store a generated API key?

In environment variables or a secrets manager—not source control, screenshots, or frontend JavaScript. In your own product, show the raw key once at creation and store a hash server-side when you issue keys to customers.

Can I generate webhook secrets here?

Yes. Use the webhook preset (whsec_ + 64 hex) or any 256-bit-class body. This creates the shared secret; HMAC signing of payloads happens in your application.

Why not use Math.random() for API keys?

Math.random() is predictable enough that later outputs can be inferred from earlier ones. API keys, session secrets, and webhook HMAC keys need a CSPRNG. This page uses crypto.getRandomValues; on a server use crypto.randomBytes or Python’s secrets module.

Should API keys go in frontend code?

Secret keys must not. Anything shipped to the browser can be extracted. Public identifiers (some pk_ publishable keys, client IDs) are designed to be public; secret keys belong on the server or in a secrets manager.

Privacy, accuracy, and trust

Privacy

API keys are generated locally with Web Crypto and are not uploaded to EverydayTools servers. Share links restore options only.

Accuracy

Randomness comes from crypto.getRandomValues with unbiased charset mapping. Prefix and suffix are user-supplied labels.

How this tool works

All generation runs in the browser. No account is required. Keys are not written to localStorage.

Developer utility. Threat model, storage, rotation, and access control remain your responsibility. Not a compliance certification and not a vendor key issuer.

Advertisement

Reviewed by EverydayTools Editorial Team on 2026-09-14.

Same workflow or intent — pick the next step without leaving the site.

Frequently opened tools from the same category.

People also use

Cross-category tools others open in the same session.

Explore categories

Browse full tool collections by topic.