Generators

API Key Generator

Secure Keys

Generate API keys

Choose a format, optional prefix, and length, then generate one or many keys instantly.
Optionsgenerated locally in your browser using crypto.getRandomValues — nothing leaves this page
Format
Prefix optional
Length random part, chars
Quantity
Entropy per key:191-bitStrong

Tool features

Secure API key generation with custom formats, prefixes, and an entropy meter
4 features

Cryptographically Secure

Keys come from the Web Crypto API with unbiased sampling

Multiple Formats

Base62, hex, and URL-safe Base64 alphabets

Custom Prefix & Length

Add a recognizable prefix and tune the random length

Entropy Meter

See the bits of entropy behind every key you generate

What is an API key & how it works

What makes a secret key safe

An API key is a long random secret that identifies and authenticates a client calling your API. Its security comes entirely from being unguessable, so it must come from a cryptographically secure random source and carry enough entropy that brute-forcing it is hopeless.

This generator draws bytes from the browser's crypto.getRandomValues and encodes them as hex, Base62 or URL-safe Base64. A readable prefix such as sk_live_ helps people and secret scanners recognise what a key is for, without weakening it. Keys are generated on your device and never sent to ShowDNS.

Entropy
Bits of unpredictability; 128 bits or more is out of reach of brute force.
Prefix
A public label like sk_live_ that marks the key type; it adds no secrecy.
Encoding
Hex, Base62 or Base64url: different alphabets for the same random bytes.

How to use this tool

Generate secure API keys in four steps
1
Pick an encoding
Choose hex, Base62 (alphanumeric) or URL-safe Base64 to suit where the key will be used.
2
Set length and prefix
Choose the length, watching the entropy meter, and an optional prefix such as sk_live_.
3
Generate
Create one key or a batch; they are generated locally in your browser.
4
Store it safely
Copy the key into your secrets manager and store only a hash of it on the server side.

Frequently asked questions

Common questions about API keys
5 Q&A

Aim for at least 128 bits of entropy, which is 32 hex characters or about 22 Base62 characters. 256 bits is a comfortable margin for long-lived keys.

Yes. They come from crypto.getRandomValues, the browser’s cryptographically secure random number generator, and are created on your device without being sent to any server.

A prefix like sk_live_ or pk_test_ tells people which system and environment a key belongs to, and lets secret-scanning tools detect leaked keys in code. It is not secret and does not count towards entropy.

Store a hash (for example SHA-256) of each key rather than the key itself, compare hashes on each request, and show the full key to the user only once when it is created.

Hex is the most portable but longest. Base62 is compact and safe everywhere without escaping. Base64url is the most compact and safe in URLs and headers.