Free online tools to generate, calculate,
convert, format, encode, and play.
 

Random Token Generator

Generate cryptographically secure random tokens for API keys, session identifiers, CSRF tokens, and more. All tokens are generated locally in your browser using the crypto.getRandomValues() API.


Click "Generate" to create a token
Options
Enter the characters to use for token generation.
History
Token Info
Encoding Hex
Length 32 chars
Charset Size 16
Entropy 128 bits
Brute Force (10B/s) Centuries+
Common Formats
  • API Key: Prefixed hex or base64 (e.g. sk_live_...)
  • Session ID: 32-64 hex characters
  • CSRF Token: 32+ URL-safe characters
  • OAuth State: Base64URL encoded random bytes
  • Nonce: Unique per-request hex or base64 value

How It Works

This tool generates cryptographically secure random tokens using the Web Crypto API (crypto.getRandomValues()). The generated bytes come from your operating system's CSPRNG (Cryptographically Secure Pseudo-Random Number Generator). Everything runs entirely in your browser - no token data is ever sent to a server.

Token vs Password vs Key

While passwords, keys, and tokens are all secrets, they serve different purposes. Passwords are memorized by humans and typed for authentication. Encryption keys are fixed-size values used by cryptographic algorithms. Tokens are opaque strings used for authorization, session management, or as unique identifiers - they are typically stored and transmitted by software, not memorized by humans.

Choosing the Right Format

  • Hexadecimal: Safe in all contexts, easy to parse. Each character encodes 4 bits of entropy. Common for session IDs and CSRF tokens.
  • Base64: More compact - each character encodes ~6 bits. Ideal for embedding in headers or JSON. May contain +, /, and = characters.
  • Base64URL: URL-safe variant (uses - and _ instead of + and /). Best for query parameters, OAuth state, and JWT components.
  • Alphanumeric: Uses A-Z, a-z, 0-9 (62 characters). Safe in URLs, filenames, and most contexts without encoding.

Recommended Token Lengths

  • Session tokens: At least 128 bits of entropy (32 hex chars or 22 base64 chars)
  • CSRF tokens: At least 128 bits of entropy
  • API keys: 32-64 characters with a recognizable prefix
  • Nonces: At least 96 bits (24 hex chars) to avoid collisions

Security Notes

  • Always use CSPRNG: Never use Math.random() for tokens - it is predictable and insecure.
  • Sufficient length: Use at least 128 bits of entropy for security-critical tokens.
  • Secure transmission: Always transmit tokens over HTTPS/TLS.
  • Proper storage: Store tokens server-side as hashed values when possible (e.g. SHA-256 of the token).
  • Expiration: Set appropriate expiration times for tokens to limit exposure if compromised.

Embed This Util

You can embed this util on your own site as a widget. Adding ?embed=1 to the URL loads a compact version with just the tool itself; no header, menu, or documentation. Paste this snippet into your HTML:


    

Copy snippet Adjust the height to taste.



Feedback

Help us improve this page by providing feedback, and include your name/email if you want us to reach back. Thank you in advance.


Share with