About 191 bits of entropy for this setting. Each character is picked independently.
Generate random tokens and secret strings online, free. This token generator creates random strings for API keys, shared secrets, test values and similar uses. You choose the length (8 to 256 characters) and the character set, and each character is chosen independently from a cryptographically secure random source (crypto.getRandomValues) with no modulo bias.
Entropy is what makes a token hard to guess. A 32-character token from letters and digits carries about 190 bits, and the tool shows the bit count for your chosen settings. 100% free, no registration, and complete privacy — everything runs locally in your browser, so your data never touches a server.
Characters come from crypto.getRandomValues, the browser's CSPRNG, not Math.random.
Bytes that would make some characters more likely are rejected, so every character in the set has the same chance.
Use letters and digits, hex, URL-safe characters (- and _), or all printable symbols, depending on where the token will be used.
Tokens exist only in the page. They are not sent anywhere, saved or logged.
The characters come from crypto.getRandomValues, which the browser provides as a cryptographically secure random number generator. Rejection sampling keeps each character equally likely. The tool shows the entropy in bits for the settings you choose.
It depends on the use. 32 characters from letters and digits (about 190 bits) is well beyond guessing for API keys. Shorter values are fine for test data but should not be used as real secrets.
Use URL-safe if the token goes into a URL or query string. Use hex if a system expects hex digits. Use letters and digits when a simple alphanumeric value is required. Use printable symbols only when the target system accepts them, because quoting and escaping can break them.
No. The token is held only in the open page until you generate another or leave the page. Nothing is sent to a server or written to storage.
The randomness is strong, but the rest of the pipeline matters too. Store secrets in your secret manager, never commit them to source control, and rotate them if they are ever shared in chat, tickets or screenshots.
We use cookies for analytics and personalized ads to help keep these tools free. Until you accept, ads stay non-personalized and analytics cookies are off. See our Privacy Policy.