Random Key
Random bytes as hex or Base64, for a secret a program will read.
Generated in this page and never sent anywhere. Nothing is stored, so reloading loses it — copy it before you leave.
16 for AES-128, 32 for AES-256 or an HMAC key.
Result
Good to know
- The strength is in the bytes, not in how they are written. The same 32 bytes are 64 hex characters or 44 of Base64, and both are exactly 256 bits.
- Base64URL is the one to pick when the key goes in a URL or a JWT: it swaps the two characters that would otherwise have to be percent-encoded, and drops the padding.
- getRandomValues fills at most 65,536 bytes per call and throws past that, so a longer key is filled in pieces here rather than coming back short.
- A key that has been in a browser tab is a key someone could have seen. For anything that matters, generate it where it will live.
33 views