Generators
API Key Generator
Generate API keys
Optionsgenerated locally in your browser using crypto.getRandomValues — nothing leaves this page
Format
Prefix optional
Length random part, chars
Quantity
Entropy per key:191-bitStrong
Tool features
4 features
Cryptographically Secure
Keys come from the Web Crypto API with unbiased sampling
Multiple Formats
Base62, hex, and URL-safe Base64 alphabets
Custom Prefix & Length
Add a recognizable prefix and tune the random length
Entropy Meter
See the bits of entropy behind every key you generate
What is an API key & how it works
An API key is a long random secret that identifies and authenticates a client calling your API. Its security comes entirely from being unguessable, so it must come from a cryptographically secure random source and carry enough entropy that brute-forcing it is hopeless.
This generator draws bytes from the browser's crypto.getRandomValues and encodes them as hex, Base62 or URL-safe Base64. A readable prefix such as sk_live_ helps people and secret scanners recognise what a key is for, without weakening it. Keys are generated on your device and never sent to ShowDNS.
Entropy
Bits of unpredictability; 128 bits or more is out of reach of brute force.
Prefix
A public label like sk_live_ that marks the key type; it adds no secrecy.
Encoding
Hex, Base62 or Base64url: different alphabets for the same random bytes.
How to use this tool
1
Pick an encoding
Choose hex, Base62 (alphanumeric) or URL-safe Base64 to suit where the key will be used.
2
Set length and prefix
Choose the length, watching the entropy meter, and an optional prefix such as sk_live_.
3
Generate
Create one key or a batch; they are generated locally in your browser.
4
Store it safely
Copy the key into your secrets manager and store only a hash of it on the server side.
Related tools
3 tools
Frequently asked questions
5 Q&A
Yes. They come from
crypto.getRandomValues, the browser’s cryptographically secure random number generator, and are created on your device without being sent to any server.A prefix like
sk_live_ or pk_test_ tells people which system and environment a key belongs to, and lets secret-scanning tools detect leaked keys in code. It is not secret and does not count towards entropy.Store a hash (for example SHA-256) of each key rather than the key itself, compare hashes on each request, and show the full key to the user only once when it is created.
Hex is the most portable but longest. Base62 is compact and safe everywhere without escaping. Base64url is the most compact and safe in URLs and headers.