How do I generate an API key online for free?
Open this generator, choose hex, Base64url, or alphanumeric, set length, click Generate, then copy. No signup—the key stays in your browser. This does not issue vendor account keys.
Each key is drawn with the Web Crypto API (crypto.getRandomValues), a CSPRNG. Generation stays in your browser. EverydayTools never receives the secret. Store it in env or a secrets manager—not git.
Skip to API key generatorGenerate a cryptographically secure API key or webhook secret in your browser. Pick hex, Base64url, or alphanumeric, add an optional prefix, and copy once. For your own APIs—not a Stripe, OpenAI, or GitHub account key.
An API key generator creates a long, random secret used to authenticate software—not a person. A secure one uses a CSPRNG such as crypto.getRandomValues, not Math.random(), and lets you choose hex, Base64url, or alphanumeric output.
US developers usually want one of two things when they search “API key generator.” Either they need a random secret for their own API (X-API-Key, a webhook HMAC secret, a local .env value), or they need a key from a vendor dashboard (Stripe, OpenAI, Google Cloud). This page does the first job only.
The generator runs in your browser with Web Crypto. You pick a format, set body length, optionally add a prefix such as sk_test_ or whsec_, then copy the result. EverydayTools never sees the key.
Generate ≥128 bits of CSPRNG material, label live vs test with a prefix, show the raw key once, and keep it out of git and frontend bundles.
Concise answers for common searches — definitions, steps, and comparisons.
Open this generator, choose hex, Base64url, or alphanumeric, set length, click Generate, then copy. No signup—the key stays in your browser. This does not issue vendor account keys.
Enough CSPRNG entropy (≥128 bits), no predictable generator, private storage, and rotation after a leak. This tool supplies the random material via Web Crypto.
No. crypto.getRandomValues runs locally. EverydayTools does not receive the generated secret.
Hex for headers and databases, Base64url for compact URL-safe tokens, alphanumeric for developer-facing keys, or classic Base64 when a stack already expects +/.
Use at least 32 hex characters (128 bits) for typical API keys. Prefer 64 hex or 43 Base64url characters (~256 bits) for webhook signing secrets.
Add sk_test_, sk_live_, or whsec_ so logs and GitHub secret scanning can recognize a leak. The random body still carries the entropy.
Generate, copy once (or copy as a .env line), then paste into a secrets manager or environment variable. Do not commit the value.
Put keys in environment variables or a secrets manager. Add .env to .gitignore. If a key hits a public repo, rotate it immediately.
Browser bundles, mobile apps, and public repos can be extracted. Only publish identifiers that are designed to be public.
When you issue keys in your own product, display the plaintext at creation, persist a SHA-256 (or stronger) hash, and compare hashes on each request.
Treat a leaked prefix in logs the same as a leak. Keep a dual-key window so old and new secrets both work while clients update.
Signing secrets are long-lived and high impact. 64 hex characters or 43 Base64url characters is cheap insurance.
Each body character is sampled with crypto.getRandomValues and rejection sampling so every alphabet symbol is equally likely. Prefix and suffix are concatenated after sampling and are not counted as entropy. No key material is sent to EverydayTools.
Formula
Entropy_bits = body_length × log2(alphabet_size)
Hex = 4 bits/char · Base64url = 6 bits/char · Alphanumeric ≈ 5.95 bits/char
Target ≥ 128 bits for typical API keys; ≥ 256 bits for long-lived signing secretsInput
Format: Hex · Length: 32 · Prefix: noneOutput
a3f82c1d4e7b09534c0e11f2b8d63a9032 hex characters = 128 bits. A solid default for generate-api-key-online workflows.
Input
Format: Alphanumeric · Length: 32 · Prefix: sk_test_Output
sk_test_Kx3fW9AbcRq7mZnP2vLdTj8YhQ5sNuLooks like a Stripe-style test key so scanners can find it. It is not a Stripe-issued credential.
Input
Format: Hex · Length: 64 · Prefix: whsec_Output
whsec_ + 64 hex characters256-bit-class body for HMAC webhook secrets you store in WEBHOOK_SECRET.
Encoding is a transport choice. Entropy is alphabet size times body length—not how fancy the string looks.
| Format | Alphabet | ~128-bit length | URL-friendly | Typical use |
|---|---|---|---|---|
| Hex | 0–9 a–f | 32 chars | Yes | Headers, databases, webhook bodies |
| Base64url | A–Z a–z 0–9 - _ | 22 chars | Yes | Compact tokens in URLs |
| Alphanumeric | A–Z a–z 0–9 | 22 chars | Yes | Prefixed developer keys |
| Base64 | A–Z a–z 0–9 + / | 22 chars | Needs care | Legacy stacks that expect +/ |
Use the page that matches the job so search intent stays clean.
| Need | Use this page | Use instead |
|---|---|---|
| Random API key or webhook secret | Yes | — |
| Human login password | No | Password Generator |
| RFC UUID / GUID identifier | No | UUID Generator |
| Signed JWT access token | No | JWT Generator |
| Generic bulk random strings | Optional | Random String Generator |
| Stripe / OpenAI / GitHub account key | No | That vendor’s dashboard |
API builders
Mint X-API-Key or shared-secret Bearer values for your own REST services and internal gateways.
Integrations
Create high-entropy secrets (often prefixed whsec_) for HMAC verification. This page creates the shared secret; your app still computes the signature.
Local development
Generate separate test keys per environment so you can rotate staging without touching production.
Fixtures
Create up to 25 keys at once for multi-tenant fixtures or local mocks. Download or copy them as .env lines.
API keys are opaque secrets. UUIDs are identifiers. JWTs are signed statements. Vendor API keys are issued by that vendor.
| Related tool | Use this tool when | Use related tool when |
|---|---|---|
| UUID Generator | You need an authentication secret or webhook signing secret. | You need RFC UUID v1/v4/v7 identifiers for databases, events, or records. |
| JWT Generator | You need an opaque shared secret string. | You need a signed JWT with claims (iss, exp, sub) for bearer auth. |
Use crypto.getRandomValues here, or crypto.randomBytes / secrets on the server.
Check bits, not vibes. Stay at or above 128 bits; use 256 bits for signing secrets.
To call Stripe, OpenAI, or Google APIs you still create a key in that product. This page only mints random secrets you control.
Use a password generator. API keys should be long and unmemorable on purpose.
Opaque keys are not JWTs. Use the JWT Generator for claim-bearing tokens.
Use the UUID Generator. A UUID can be an opaque ID; this page is for auth secrets.
Sign in to that vendor and create the key there. A random string from this page will not authenticate their API.
Continue the workflow with the right follow-up tool.
Advertisement
No. Account keys come from that vendor’s dashboard after you sign in. This tool only creates a random secret for your own app, mocks, or webhook HMAC. Style presets such as sk_test_ copy a common prefix so scanners can recognize leaks—they are not Stripe or GitHub credentials.
Use a CSPRNG, not Math.random(). On this page, pick a format, set a body length that reaches at least 128 bits (32 hex or about 22 Base64url characters), optionally add a prefix, then generate and copy. The key is created with crypto.getRandomValues in your browser.
No. Generation is client-side only. EverydayTools does not receive, log, or save your keys. A share link copies options (format, length, prefix)—never the secret. Confirm in the browser Network tab while you generate.
Aim for at least 128 bits of entropy: 32 hex characters, about 22 Base64url characters, or about 22 alphanumeric characters. Use 64 hex or 43 Base64url characters (~256 bits) for long-lived webhook or master secrets.
All are fine with a CSPRNG. Hex is safest in URLs and headers. Base64url is denser and URL-safe. Alphanumeric is common for developer-facing keys with prefixes. Classic Base64 is denser too but +/ often needs encoding in URLs.
An API key is usually a long-lived opaque secret. “Token” may mean the same thing or a short-lived OAuth credential. A JWT is a signed statement with claims (iss, exp, sub). This page generates opaque random secrets—not signed JWTs.
Yes for operations. Distinctive prefixes help humans and secret scanners notice a leak in git or logs. They do not replace entropy in the random body and they do not turn the string into a vendor-issued key.
Yes when it uses Web Crypto (crypto.getRandomValues) and does not transmit the key. Avoid any generator that still uses Math.random() for production secrets. Your storage, rotation, and access control still matter after you copy the value.
In environment variables or a secrets manager—not source control, screenshots, or frontend JavaScript. In your own product, show the raw key once at creation and store a hash server-side when you issue keys to customers.
Yes. Use the webhook preset (whsec_ + 64 hex) or any 256-bit-class body. This creates the shared secret; HMAC signing of payloads happens in your application.
Math.random() is predictable enough that later outputs can be inferred from earlier ones. API keys, session secrets, and webhook HMAC keys need a CSPRNG. This page uses crypto.getRandomValues; on a server use crypto.randomBytes or Python’s secrets module.
Secret keys must not. Anything shipped to the browser can be extracted. Public identifiers (some pk_ publishable keys, client IDs) are designed to be public; secret keys belong on the server or in a secrets manager.
API keys are generated locally with Web Crypto and are not uploaded to EverydayTools servers. Share links restore options only.
Randomness comes from crypto.getRandomValues with unbiased charset mapping. Prefix and suffix are user-supplied labels.
All generation runs in the browser. No account is required. Keys are not written to localStorage.
Developer utility. Threat model, storage, rotation, and access control remain your responsibility. Not a compliance certification and not a vendor key issuer.
Advertisement
Reviewed by EverydayTools Editorial Team on 2026-09-14.
Same workflow or intent — pick the next step without leaving the site.
Free UUID generator: v4, v7 & v1 GUIDs in your browser—bulk up to 1,000, validate, export JSON/CSV. crypto.randomUUID; never uploaded.
Free .env file parser — paste any .env file and extract all environment variables as structured JSON or YAML. Useful for config migration and debugging. No signup needed. Runs locally in your browser when supported—no upload required for normal use.
Design a mock REST response in your browser—JSON body, status, headers, and delay. Copy Express or MSW snippets. Free, no signup. Does not host a live API URL.
Free number base converter: binary, decimal, octal, hex, and custom bases 2–36. Live convert with BigInt for large integers. Browser-local, no signup.
Encode text to Base64 or decode a Base64 string online. UTF-8 safe, with URL-safe Base64. Runs in your browser—no upload, no signup.
See your browser name and version in one second—plus OS, screen size, and user agent. Copy for support; runs locally with nothing uploaded.
Frequently opened tools from the same category.
Free JSON formatter — paste minified or messy JSON and instantly get beautified, indented output with syntax highlighting and error detection. Browser-based, no server upload. Runs locally in your browser when supported—no upload required for normal use.
Free JSON diff & compare — structural side-by-side diff, ignore paths, array modes, RFC 6902 patch and merge patch export. Runs locally in your browser—no upload.
Free UUID generator: v4, v7 & v1 GUIDs in your browser—bulk up to 1,000, validate, export JSON/CSV. crypto.randomUUID; never uploaded.
Free random number generator — Web Crypto integers or decimals, no-repeat draws, dice, coin flip, and list picker. Copy or CSV. Runs locally in your browser.
Cross-category tools others open in the same session.
What is 20% of 500? Percent increase, decrease, difference, reverse %, markup & margin—runs locally in your browser, no upload. Copy results or share a link.
Free JSON formatter — paste minified or messy JSON and instantly get beautified, indented output with syntax highlighting and error detection. Browser-based, no server upload. Runs locally in your browser when supported—no upload required for normal use.
Free word counter — live word, sentence, and paragraph counts plus reading time for essays, blogs, and SEO drafts. Runs locally in your browser.
Free adult BMI from height and weight (lb/ft/in or kg/cm). CDC category, healthy weight range, optional waist. Screening only—runs in your browser.
Browse full tool collections by topic.
Secure API key generator