API Key Generator

Strong API keys and secrets with prefix support — sk_test_, pk_live_, or your own. Configurable length and charset, bulk mode.

Presets
Prefix
Charset
Body length32 chars · ~192 bits · strong
How many
Press Generate

Pick a preset or customize, then Generate.

01 — Overview

How the API Key Generator works

Generate API keys and secret tokens with prefixes like sk_test_ or pk_live_ so they're scannable in logs. Pick a charset (alphanumeric, base64url, hex), set the length, and generate one or many. All randomness uses the Web Crypto API; keys never leave your browser.

02 — Use cases

When to use the API Key Generator

  1. 01

    Issue a fresh test API key for a service in seconds

  2. 02

    Bulk-generate keys for seeding a multi-tenant test database

  3. 03

    Get a high-entropy bearer token for local dev

  4. 04

    Mint a webhook signing secret

03 — Examples

API Key Generator examples

prefix sk_test_, base64url, 32 chars

ex 01

sk_test_a3F7zq8KvR2NxLp9wYbT5cM1jE0HsViD

Stripe-style test secret key.

no prefix, hex, 64 chars

ex 02

9f2c8a1e4b7d6035e8c2a7f1b9d4e5c3a6f8b2d7e1c4a9b3f5d8e2c6a4b1f9d3

256 bits of hex entropy — webhook signing material.

prefix whsec_, hex, 64 chars

ex 03

whsec_4f2c9a1e7b3d80652fc8e1a94b7d6035e8c2a7f1b9d4e5c3a6f8b2d7e1c4a9b3

Webhook signing secret — 256 bits, with a prefix scanners can recognise.

10 × keys, base64url, 43 chars

ex 04

10 distinct 256-bit keys, one per line

For seeding a multi-tenant fixture where every tenant needs its own key.

04 — FAQ

API Key — frequently asked questions

How much entropy do I need?

128 bits is comfortably resistant to brute force. Length depends on charset: 22 base64url chars ≈ 128 bits; 32 hex chars = 128 bits. The tool shows entropy live so you can size the key to your threat model.

Why use a prefix?

Prefixes (sk_test_, pk_live_, ghp_, etc) make keys scannable in logs and source code — secret scanners use them to detect leaked credentials. They cost a few characters of length but pay back many times over in incident response.

Are these keys safe?

The randomness uses window.crypto.getRandomValues — the same source recommended for security-sensitive use in the browser. Keys never reach a server.

How should I store an API key on the server?

Store a hash of it, not the key. Show the full value to the user exactly once at creation, keep a hash plus a short display prefix for the UI, and verify incoming keys by hashing them. Then a database leak doesn't hand over working credentials, and you can still show users which key is which.

What's a good prefix convention?

Something like service_env_ — sk_live_, sk_test_, whsec_. Two things fall out of it: a key in a log or a screenshot is instantly identifiable, and secret scanners can be taught the pattern. GitHub's secret scanning works this way, and a distinctive prefix means a leaked key gets flagged rather than sitting in a public repo.

How much entropy does a key need?

128 bits is the practical floor and 256 bits costs you nothing extra. That's 22 characters of base64url or 32 hex characters at the low end. The length only matters if the randomness is real — a 64-character key from a weak source is weaker than a 22-character one from Web Crypto.

05 — Reference

Specs and further reading

The primary sources this tool follows. Where behaviour is defined by a specification, we link the specification rather than a summary of it.

07 — More

Tools that pair with API Key

Last updated .