Skip to content
FlexibleToolsAI
Security Toolkit · 100% Client-Side Private

API Key Generator

Create API keys for your own service: a recognisable prefix (sk_live_, pk_test_…), 192+ bits of cryptographically secure randomness in Base62, and an optional checksum suffix — the design used by Stripe and GitHub so keys are easy to identify and leaked keys are easy to detect.

Set a prefix, strength and encoding, choose whether to append a checksum, and copy the keys. The prefix tells users and secret scanners what the key is; the checksum lets your API reject mistyped or fake keys without a database lookup. Store only a hash of each key on your server.

optional

API keys

    192 bits from crypto.getRandomValues, generated in your browser and never sent anywhere. 128 bits or more is infeasible to guess.

    Store only a hash (e.g. SHA-256) of each API key in your database, show the full key to the user once, and keep a short non-secret prefix to identify it. A recognisable prefix (like sk_live_) also lets secret scanners detect leaked keys in code.

    Zero Server Uploads

    Files process in local RAM

    Instant WASM Speed

    No waiting queues or lags

    Unlimited Batching

    Convert files without limits

    Suggest a Feature or Improvement for API Key Generator

    Need custom options, higher limits, or extra format support? Let our engineering team know!

    How to use API Key Generator

    1. 1Enter a prefix such as sk_live_ or myapp_.
    2. 2Pick the strength (192–256 bits) and encoding.
    3. 3Keep the checksum option on for GitHub-style keys.
    4. 4Copy the keys and store only their hashes server-side.

    Designing good API keys

    Use a vendor prefix so keys are recognisable in logs and can be registered with GitHub secret scanning; distinguish environments (live/test) and key types (secret/publishable); make them long and random (at least 128 bits); and use URL- and copy-safe characters.

    Show the full key to the user once, then store a SHA-256 hash of it. On each request, hash the presented key and look it up — like a password, but fast hashing is fine because the key is high-entropy.

    Why a checksum?

    GitHub appends a CRC32 checksum to its tokens so tools can tell a real token from random text with almost no false positives, and your API can reject typos instantly. Generic secrets without a format are available in the Secure Token Generator.

    Frequently Asked Questions

    Where do I get a Google, OpenAI or Gemini API key?

    Those keys can only be issued by the provider from its own console — a generator can't create a working key for someone else's service. This tool creates keys for APIs you run yourself.

    How should I store API keys?

    Store a hash (SHA-256) plus a short non-secret prefix for display. Never log full keys, and let users revoke and rotate them.

    Is my data sent to your server?

    No. This tool runs entirely in your browser using the Web Crypto API and JavaScript. Nothing you type or generate is uploaded, logged or stored.

    Related Tools