Random API Key Generator
Generate up to 10 random API key strings at a time, 1 to 100 characters long, with your choice of letters, digits and symbols.This tool produces random strings shaped like API keys. Set how many you want (1 to 10), the length (1 to 100 characters, 32 by default) and which character classes to include, then press Generate API Key. Each key appears on a card with a copy button. Everything runs in your browser; nothing is sent to a server or stored, so the keys you see exist only on your screen until you copy them.
Options
- Number of keys: 1 to 10 per click.
- Length: 1 to 100 characters. 32 is the default because many real API keys are 32 or 40 characters; 64 is common for secrets.
- Include: lowercase letters, uppercase letters, numbers and special characters. Lowercase, uppercase and numbers are on by default; special characters are off, since most APIs expect keys that are safe in URLs and headers. At least one class has to stay checked. The symbol set is
!@#$%^&*()_+~`|{}[]:;?<>,./-=.
With the default settings each character is one of 62 possibilities, so a 32-character key has 6232 combinations, roughly 190 bits. There is no prefix option: if you want a key that looks like sk_test_… or AKIA…, generate the random part here and add the prefix yourself.
What it is good for, and what it is not
The characters are picked with the browser's Math.random(), which is fast and fine for anything where unpredictability is not a security requirement: placeholder keys in documentation and screenshots, fixtures for unit tests, seed data for a staging database, dummy values in a .env.example, or a token for a throwaway local service. It is not a cryptographically secure random number generator, so do not use these strings as production secrets, signing keys or anything an attacker would gain from guessing. For real credentials generate the key on the server with a CSPRNG (openssl rand -hex 32, Node's crypto.randomBytes, Python's secrets.token_urlsafe) or let the API provider issue it.
How real API keys are shaped
Providers do not share a standard, but a few patterns are common and useful to imitate in test data. Many services use a short prefix that identifies the key type followed by a random body: Stripe keys start with sk_live_ or pk_test_, AWS access key IDs are 20 uppercase alphanumerics starting with AKIA, GitHub personal tokens start with ghp_, and OpenAI keys with sk-. The random body is usually base62 (letters and digits), base64url or hex, and 32 to 64 characters long. Hex keys only use 0-9a-f, so to imitate one here, turn off uppercase and accept that the letters will run past f; for a strict hex string use the Random String Generator with a custom character set instead.
Typical uses
- Mock responses. A fake
{"api_key": "…"}payload for a front-end that is not wired to a back end yet. - Documentation. Example keys in a README or API reference that look right but cannot be mistaken for a real credential.
- Seed data. Ten keys at a time for a test table of users or integrations.
- Local dev secrets. A value for
SESSION_SECRETon a laptop where the only threat model is a typo.
Related tools: the Encryption Key Generator for fixed-size keys, the Random Code Generator for short voucher-style codes, and the Random User Agent Generator and Random MAC Address Generator for other request-level test values. See all developer & test data tools for the full list.
Frequently asked questions
- Is it safe to use these keys in production?
No. They are generated with Math.random(), which is not cryptographically secure. Use them for tests, docs and local development. For production secrets, generate keys with a CSPRNG on your server or use the key your API provider issues.
- Can I generate a secret key or token of a specific length?
Yes. The length field accepts 1 to 100 characters. For a 64-character secret set the length to 64; for a 40-character token set it to 40.
- Are the generated keys stored anywhere?
No. Generation happens in your browser and nothing is sent to our servers or kept after you leave the page. Copy a key before you generate again, because the previous set is replaced.
- Why can't I uncheck the last character type?
A key needs at least one character class to draw from, so the tool keeps the last checked box on. Check another class first if you want to change which one is used.



