Secret Key Generator

Generate random strings for API keys, session secrets, and passwords. Pick the length and which character sets to include, and see how much entropy the result actually carries in bits.

Length

32 chars

Character sets

Symbols: !#%*+-.:=?@^_~

How many

Generated keys

~0 bits · Short. Unless a human has to memorise it, make it longer

    Generated in your browser and sent nowhere. Randomness comes from crypto.getRandomValues — Math.random is predictable and must never be used for keys. At least one character from each selected set is included, then the whole string is shuffled so the positions are not biased.

    Length and character sets

    Length is the 16, 32 or 64 button, or anywhere from 8 to 128 on the slider. The sets are digits (10), lower (26), upper (26) and symbols (14), and every enabled set contributes at least one character — drawn purely at random, a key with symbols enabled could contain none, and a system that demands one would reject it. Count is 1, 5 or 10, and with several keys "Copy all" joins them with line breaks.

    How the bits are counted

    It is length × log2(number of characters available), rounded down. With all four sets that is 76 characters, about 6.25 bits each. Below 64 bits is "short", below 128 is "fine", and above that "plenty" — with all four sets, 16 characters is 99 bits and 32 is 199. The guarantee of one character per set is not part of this calculation.

    Dropping look-alike characters

    When on, 0, O, 1, l and I are removed from every set. It is for keys someone will copy by hand. The alphabet shrinks from 76 to 71, so the bit count at a given length drops slightly.

    Generated in the browser, sent nowhere

    Randomness comes from crypto.getRandomValues. Keys go to no server and are not stored, so a reload produces different ones and earlier keys cannot be recovered. To draw again with the same settings, press "Generate again".

    Frequently asked questions

    Why so few special characters?

    Only the ones that survive being pasted somewhere are included. In a shell, $ expands as a variable and backticks execute as a command. Quotes and backslashes terminate strings, and / is a path separator in URLs. The same problems appear in .env files. The alphabet gets a little smaller, but adding a character or two of length more than makes up for it.

    Is the randomness safe?

    It uses crypto.getRandomValues. Math.random is predictable and must never generate a key — observing a handful of values from the same browser is enough to predict the next one. The modulo bias that appears when mapping random bytes onto an alphabet is eliminated as well.

    How many bits are enough?

    Anything above 128 bits is comfortable; below 64 is short. With uppercase, lowercase, digits, and symbols all enabled, each character carries about 6 bits, so 32 characters comes to roughly 199 bits. The figure is shown on screen while you adjust the settings.

    Why does digits-only come out as "short"?

    There are only ten digits, so each carries about 3.32 bits; 16 of them is 53 bits, under 64. Digits alone need 20 characters to reach "fine" and 39 to reach "plenty".

    I enabled symbols and got only one. Is that wrong?

    No. Each set is guaranteed one character; beyond that it is random. Symbols are 14 of the 76 characters, so about six in a 32-character key is the average, and a single one does happen.

    Does anything I paste get sent to a server?

    No. Everything runs inside your browser and nothing is uploaded or stored. That is why you can use it on things you would not normally paste into a web page, like an internal config file or a production query. It also works with your network disconnected.