API Key Generator
Create API keys for your own service: a recognisable prefix (sk_live_, pk_test_…), 192+ bits of cryptographically secure randomness in Base62, and an optional checksum suffix — the design used by Stripe and GitHub so keys are easy to identify and leaked keys are easy to detect.
Set a prefix, strength and encoding, choose whether to append a checksum, and copy the keys. The prefix tells users and secret scanners what the key is; the checksum lets your API reject mistyped or fake keys without a database lookup. Store only a hash of each key on your server.
API keys
192 bits from crypto.getRandomValues, generated in your browser and never sent anywhere. 128 bits or more is infeasible to guess.
Zero Server Uploads
Files process in local RAM
Instant WASM Speed
No waiting queues or lags
Unlimited Batching
Convert files without limits
Suggest a Feature or Improvement for API Key Generator
Need custom options, higher limits, or extra format support? Let our engineering team know!
How to use API Key Generator
- 1Enter a prefix such as sk_live_ or myapp_.
- 2Pick the strength (192–256 bits) and encoding.
- 3Keep the checksum option on for GitHub-style keys.
- 4Copy the keys and store only their hashes server-side.
Designing good API keys
Use a vendor prefix so keys are recognisable in logs and can be registered with GitHub secret scanning; distinguish environments (live/test) and key types (secret/publishable); make them long and random (at least 128 bits); and use URL- and copy-safe characters.
Show the full key to the user once, then store a SHA-256 hash of it. On each request, hash the presented key and look it up — like a password, but fast hashing is fine because the key is high-entropy.
Why a checksum?
GitHub appends a CRC32 checksum to its tokens so tools can tell a real token from random text with almost no false positives, and your API can reject typos instantly. Generic secrets without a format are available in the Secure Token Generator.
Frequently Asked Questions
Where do I get a Google, OpenAI or Gemini API key?
Those keys can only be issued by the provider from its own console — a generator can't create a working key for someone else's service. This tool creates keys for APIs you run yourself.
How should I store API keys?
Store a hash (SHA-256) plus a short non-secret prefix for display. Never log full keys, and let users revoke and rotate them.
Is my data sent to your server?
No. This tool runs entirely in your browser using the Web Crypto API and JavaScript. Nothing you type or generate is uploaded, logged or stored.
Related Tools
Secure Token Generator
Generate cryptographically secure random tokens and secrets in hex, Base64url, Base62 or Base32.
UUID Generator
Generate UUID v4 and v7, ULID, CUID2 and NanoID in bulk — and decode any UUID.
HMAC Generator
Generate and verify HMAC signatures with SHA-256, SHA-512, SHA-1, MD5 or SHA-3.