Secret Generator
Generate cryptographically secure secrets β API keys, tokens, passwords, and passphrases. Everything is generated in your browser with the Web Crypto API, so nothing is ever sent over the network or stored.
Hex and Base64 are the direct equivalents of openssl rand β good for API keys, signing keys, and app secrets.
Base64 (URL-safe) swaps + / for - _ and drops padding, for tokens that live in URLs.
Password draws random characters from a set you choose. Passphrase picks random words β easier to type and say aloud.
How many random bytes to generate, exactly like the number in openssl rand -hex 32.
32 bytes (256 bits) is the usual choice for app secrets and signing keys.
Leaves out I l 1 O 0 β the characters people mix up when reading a secret aloud or typing it from a screen.
Generated with crypto.getRandomValues(), the browser's cryptographically secure random source.
It is never sent anywhere and never saved β refresh the page and it is gone.
The nearest command-line equivalent, for scripts, Dockerfiles, and CI config.
It generates the same kind of secret β not the identical value shown above.