Encryption Key Generator

Get up to ten random 256-bit keys, each 32 secure random bytes shown as 64 hex characters, with a copy button.

Enter how many keys you want (1 to 10) and press Generate Encryption Key. Each result is 32 bytes of cryptographically random data shown as a 64-character hexadecimal string, which is exactly the size of an AES-256 key. The keys are produced in your browser from a secure random source; nothing is sent to or stored on a server. Every card has a copy button so a key can go straight into a config file, environment variable or key-management tool.

What the tool produces

One key type, at one size: 256 bits, hex-encoded. A sample looks like 9f86d081884c7d659a2feaa0c55ad015a3bf4f1b2b0b822cd15d6c15b0f00a08. That's 32 bytes, each written as two hex digits (0–9, a–f). There's no option for 128-bit or 192-bit keys, no Base64 output, and no passphrase-derived keys. If you need a 16-byte AES-128 key, take the first 32 hex characters of a generated key; the bytes are independent, so a prefix is just as random as the whole. If you need Base64, convert the hex once you've copied it (xxd -r -p | base64 on a Unix shell does it).

The generator calls randomBytes(32) from the crypto library, which draws from the operating system's cryptographically secure random number generator rather than a seeded math routine. That's the property that matters for a key: an attacker who knows how the tool works still can't predict the output.

Where a key like this is used

  • AES-256 encryption in any mode (GCM, CBC, CTR). Libraries such as Node's crypto, Python's cryptography, OpenSSL and Java's JCE accept a 32-byte key; decode the hex first.
  • HMAC secrets for signing tokens or webhooks. HMAC-SHA256 works well with a 32-byte secret.
  • Application secrets such as a Django SECRET_KEY, a Rails secret_key_base, a JWT signing secret or a session-cookie key, where the framework just wants a long unpredictable string.
  • Database and file encryption keys for tools that accept a hex master key in configuration, for example encrypted SQLite extensions or backup utilities.
  • Test fixtures. Ten distinct keys in one click for unit tests that exercise key rotation. For shorter random identifiers, the Random String Generator and Random API Key Generator are better fits.

Key sizes, for reference

Algorithm / useKey lengthHex charactersFrom this tool
AES-12816 bytes (128 bits)32Use the first 32 characters
AES-19224 bytes (192 bits)48Use the first 48 characters
AES-25632 bytes (256 bits)64Use the whole key
HMAC-SHA256 secret32 bytes recommended64Use the whole key
ChaCha20-Poly130532 bytes (256 bits)64Use the whole key

Handling the key after you copy it

The generator's job ends when the key is on your clipboard, and the rest is up to how you store it. A few practices that avoid the common mistakes: don't paste the key into source code that gets committed; put it in an environment variable, a secrets manager or an encrypted config. Generate a separate key per environment so a leaked staging key doesn't unlock production. Remember that AES modes like GCM and CBC also need a nonce or IV that must be unique per message; that value is not a key and should not be reused, so don't use a generated key as an IV. And if a key is ever exposed, rotating it means re-encrypting the data it protected, not just replacing the string.

Other developer utilities on the site follow the same pattern: the Random MAC Address Generator and Random IP Generator for network test data, and the Random Code Generator for short alphanumeric codes. See all developer and test data tools for the full set.

Frequently asked questions

Is this an AES-256 key generator?

Yes. Each key is 32 random bytes (256 bits) written as 64 hex characters, which is the exact key size AES-256 requires. Decode the hex to bytes before passing it to your encryption library.

Can I generate a 128-bit key?

There's no size option, but you can use the first 32 hex characters (16 bytes) of any generated key as an AES-128 key. Each byte is independently random, so a prefix is as secure as a full-length key of that size.

Are the keys generated on a server? Could someone else see them?

No. Keys are created in your browser using the crypto library's secure random source and are never transmitted or logged. Once you leave the page they're gone unless you copied them.

Is the output secure enough for production use?

The randomness comes from a cryptographically secure generator, so the key material itself is suitable for production. How you store, transmit and rotate it matters just as much; keep it out of source control and use a secrets manager where you can.

Can I get the key in Base64 instead of hex?

Not directly. Copy the hex and convert it: on macOS or Linux, echo the key into `xxd -r -p | base64`; in Node, use Buffer.from(hex, 'hex').toString('base64').