CSRF Token Generator
Generate cryptographically secure anti-CSRF tokens for tests and fixtures, and — more importantly — copy correct code to generate them per session in your own app, with a short explanation of how CSRF protection works.
Choose a strength (256 bits by default) and encoding to generate tokens, and copy the snippet for your language. A real CSRF token must be generated on your server for each session, embedded in forms or sent as a header, and compared on the server for every state-changing request.
CSRF tokens
256 bits from crypto.getRandomValues, generated in your browser and never sent anywhere. 128 bits or more is infeasible to guess.
Generate CSRF tokens in your app
import { randomBytes } from 'node:crypto';
// Per session: store in the session, render into forms/headers
const csrfToken = randomBytes(32).toString('base64url');A CSRF token must be generated on the server, tied to the user's session, sent with each form or request (hidden field or header) and compared on the server. Tokens from this page are for testing and fixtures. Combine with SameSite=Lax cookies; most frameworks (Django, Laravel, Rails, Spring) have CSRF protection built in.
Zero Server Uploads
Files process in local RAM
Instant WASM Speed
No waiting queues or lags
Unlimited Batching
Convert files without limits
Suggest a Feature or Improvement for CSRF Token Generator
Need custom options, higher limits, or extra format support? Let our engineering team know!
How to use CSRF Token Generator
- 1Generate tokens for testing, or pick your language.
- 2Copy the server-side snippet.
- 3Store the token in the session and add it to forms or a request header.
- 4Reject requests where the submitted token doesn't match.
How CSRF protection works
Cross-site request forgery tricks a logged-in user's browser into sending a request to your site from another site. A CSRF token is a secret, unpredictable value tied to the user's session: attacker pages can't read it, so forged requests don't include it and are rejected.
Modern defences combine SameSite=Lax (or Strict) cookies with tokens or origin checks. Frameworks like Django, Laravel, Rails, Spring Security and ASP.NET include CSRF protection — use it rather than rolling your own.
Common mistakes
Using predictable tokens (timestamps, user IDs), sending them in GET URLs where they leak via Referer, or checking only that a token exists rather than that it matches. Compare tokens with a constant-time comparison. Check your cookies' SameSite settings with the Cookie Security Checker.
Frequently Asked Questions
Can I use a token from this page in production?
No — CSRF tokens must be generated per session by your server. Tokens here are for testing and learning.
Is SameSite enough on its own?
SameSite=Lax blocks most cross-site POSTs, but tokens add defence in depth against same-site attacks, older browsers and GET requests that change state.
Is my data sent to your server?
No. This tool runs entirely in your browser using the Web Crypto API and JavaScript. Nothing you type or generate is uploaded, logged or stored.
Related Tools
Secure Token Generator
Generate cryptographically secure random tokens and secrets in hex, Base64url, Base62 or Base32.
Cookie Security Checker
Check a site's cookies for Secure, HttpOnly, SameSite, prefix and scope issues.
JWT Generator
Create and sign JSON Web Tokens with HS256, RS256, ES256 and more — in your browser.