Skip to content
Browse tools

Random Token Generator

API keys, session secrets, nonces and reset tokens — generated from your browser's cryptographic random source in whichever encoding your stack expects.

Latest token —

⚙️ Format & Size

Random bytes
32

🔑 Generated Tokens

🔒 Generated on your device, never transmitted. Tokens come from crypto.getRandomValues() — the browser's cryptographically secure generator. Nothing is sent to our server, so you can safely generate production secrets here. Do check your browser extensions, though: anything with page-read access could see the result.
HOW IT WORKS

Bytes, Not Characters

The strength of a token comes from how many random bytes back it, not how long the string looks. 32 random bytes is 256 bits of entropy regardless of whether you render it as 64 hex characters or 43 Base64url ones — the encoding changes the length, never the security. That's why the control above asks for bytes: 16 bytes (128 bits) is fine for a session ID or nonce, and 32 bytes (256 bits) is the usual choice for API keys and anything long-lived. Base64url matters specifically because it swaps + and / for - and _ and drops padding, so the token survives being put in a URL or filename without escaping.

What else can you check?

These tools all work on the same connection and address data — pick whichever question you actually have.

Want to see the full path to a site? DNS, redirects, every hop, the CDN, TLS and the origin server. Want to know your public IP? See your IPv4 and IPv6 addresses, location, ISP and ASN. Want to check your tower & route? Live ping, speed, DNS, traceroute and a map of nearby points. Want to ping from around the world? Real latency from real probes across 12 countries, live on a map. Want to locate any IP address? City, region, country and coordinates for any public IP. Want to know if an IP is risky? Proxy, VPN, Tor, hosting and abuse-report indicators. Want to know if you're blacklisted? Check an address against major spam and abuse DNSBLs. Want to know who owns an IP? Network owner, ASN, CIDR range and abuse contact. Want to explore an AS number? Announced prefixes, BGP neighbours and registry details. Want to test your connection speed? Measure real download, upload, ping and jitter. Want to see what changed? Word-level diff between two blocks of text or code. Want to know if a DNS change is live yet? Compare answers from five independent public resolvers. Want to verify a domain's nameservers? Direct authoritative checks, glue records and SOA serials. Want to check a domain's DNSSEC setup? DNSKEY, DS records, signature expiry and real validation. Want to see the hop-by-hop path to a server? A real traceroute from a genuine probe anywhere in the world. Want to know if a server port is open? A real TCP connection attempt - open, closed or filtered. Want to measure latency to a server? Real connect timing - min/avg/max, jitter and connection loss. Want a clean URL slug from a title? Real transliteration, stop words and batch mode. Want to find and replace across a document? Regex, capture groups and a live preview before you commit. Want to find the invisible character? Code points, escapes, bytes and hidden-character detection. Want to escape text for HTML? Minimal, named or numeric entities, attribute-safe. Want to strip emoji cleanly? Whole clusters - no half-flags or stray modifiers left. Want to spot repeated words? Frequency, density and accidental doubles like "the the". Want to know if a URL is cached? Two requests prove whether your CDN is really caching it. Want to see what a site knows about you? Storage, cookies, tokens and what your browser actually cached. Want to run that check on any site? One-click bookmarklet reads storage and tokens where they live. Want to know who your site talks to? Renders the page and names every outside company it contacts. Is your site one address or four? www, non-www, http and https - which serve, which redirect. Need to build an Authorization header? Basic, Bearer, API key, Digest and AWS SigV4 - signed in your browser. Want to tidy up a messy SQL query? Beautify, minify, lint and convert keyword casing for six dialects. Need to work out a percentage? Nine calculators covering every way a percentage gets asked. Want to work out a rise or a raise? Increases, growth, compounding and CAGR, with the working shown. Want to work out a discount or a drop? Discounts, stacked sales and depreciation, with the working shown. What is actually on that page? Words, reading time, readability, every image, embed and link. Need a favicon that works everywhere? Every size, a real multi-resolution .ico, and the tags to paste. What headers does a site send back? Every response header on every redirect hop, explained. Need to test a regular expression? Live matches, capture groups, replace preview and code snippets. Need a JPG as a PNG? Batch convert in your browser, with optional transparent background. Need somewhere to jot things down? Private notes, links, to-dos and reminders saved in your browser. Need just some pages of a PDF? Split by page, range or chunk, or extract the pages you pick. What is hiding inside that image? EXIF camera settings, GPS tags, colour palette and web checks.
COMMON QUESTIONS

Token Generator FAQ

How many bytes should I use?

16 bytes (128 bits) is sufficient for session identifiers, CSRF tokens and nonces. 32 bytes (256 bits) is the standard for API keys, signing secrets and password-reset tokens. Going beyond 64 bytes adds length but no meaningful security.

What's the difference between Base64 and Base64url?

Standard Base64 uses +, / and = padding, all of which need escaping in URLs and are invalid in filenames. Base64url replaces them with - and _ and omits padding, so the token can be dropped into a query string or path unchanged.

Is UUID v4 safe to use as a secret?

It's random, but only 122 of its 128 bits are — six are fixed version and variant markers. That's still strong, but UUIDs are designed for uniqueness rather than secrecy and are often assumed non-sensitive by logging tools. For an actual secret, prefer a 32-byte token.

Why does the alphanumeric option produce a different length?

Because it encodes into 62 characters rather than 16 or 64, so the same entropy needs a different number of characters. The entropy figure shown below the list is the honest measure in every format.

Can I trust a website with my production secrets?

Only when you can verify nothing leaves the page — which you can here by opening your browser's network tab while generating. That said, the most cautious approach for the highest-value secrets is always your own machine: openssl rand -hex 32 does the same job offline.