-تُنشأ محليًا عبر crypto.getRandomValues - لا تُرسل أبدًا.
(التوثيق بالإنجليزية)
What it does
The Secure Token Generator produces cryptographically-random tokens for API keys, session secrets, share links, and one-time passwords. You set the amount of randomness in bytes and the output format (hex, base32,
base64base64An encoding representing binary data as 64 safe ASCII characters, so it survives transport through text-only channels. It encodes — it does not encrypt.
, base62, or alphanumeric), and it shows the resulting string plus its true strength in bits. Generation uses the browser’s CSPRNG (crypto.getRandomValues) and never leaves your device, so it is safe for real secrets.
How to use it
- Set
EntropyEntropyThe unpredictability of a secret, measured in bits. Each added bit doubles the guesses an attacker needs; strength comes from length and randomness, not from obscurity.
(bytes) - 16 bytes (128 bits) is the standard for most tokens; 32 bytes (256 bits) for high-value keys. - Pick a Format - hex for
checksumschecksumsA short digest computed from a block of data, compared after transfer or storage to detect corruption. Changing one bit changes the checksum.
/IDs, base64url for compact web tokens, base32 when humans may type it. - Choose a Variant where offered (hex case,
base64base64An encoding representing binary data as 64 safe ASCII characters, so it survives transport through text-only channels. It encodes — it does not encrypt.
vs URL-safe, base32 alphabet). - Copy the token, or hit Regenerate for a new one. The URL captures your settings so you can share the exact configuration.
Examples
128-bit hex token (16 bytes)
Format: Hex → 32 characters, e.g. 9f4a2c7b8e1d0f3a5b6c7d8e9f0a1b2c - strength: strong · ~128 bits.
256-bit base64url token (32 bytes)
Format: Base64 → URL-safe, 43 characters, e.g. v8aM2dQfTn_YpKxR4sLz9BwEhJm6UcAo3NqVbGi - strength: very strong · ~258 bits.
Crockford base32 (20 bytes)
Format: Base32 → Crockford (no I/L/O/U, unambiguous to read aloud), 32 characters - strength: strong · ~160 bits.
Good to know
- No modulo bias: each symbol is selected with rejection sampling, so even non-power-of-two alphabets (base62, alphanumeric) stay uniformly random.
- Private: all randomness is generated locally and never transmitted - safe for production secrets.
- Related tools: Password Generator,
UUIDUUIDA 128-bit identifier generated to be practically unique without coordination, most commonly in version-4 (fully random) form.
Generator,HashHashA one-way function that maps data of any size to a fixed-length digest. Same input, same digest; any change, different digest; not reversible.
Generator.