Random Token Generator

Generate UUID v4 values, hex and Base64 tokens, alphanumeric strings, sk_-prefixed API-key style strings and passwords, up to 50 at a time, from the browser's cryptographic random generator.

Last updated

About the Random Token Generator

Pick a token type, set the length and count, and press Generate. Six formats are available:

UUID v4 produces standard 36-character identifiers such as 3f2b8c1e-9d4a-4b7f-8e21-5c6d7a9b0f12, with 122 random bits. Hex Token uses 0–9 and a–f (4 bits per character, so 32 characters give 128 bits). Base64 Token uses A–Z, a–z, 0–9, + and / (6 bits per character, no = padding). Alphanumeric uses letters and digits. API Key gives sk_ followed by 32 letters and digits (about 190 bits). Secure Password mixes letters, digits and 26 symbols.

Everything comes from the Web Crypto API. UUIDs use crypto.randomUUID() where the browser offers it; otherwise a version 4 UUID is built from 16 bytes of crypto.getRandomValues, with the version and variant bits set as the standard requires. The other types draw from crypto.getRandomValues and discard values that would make some characters more likely than others.

Developers use it to fill a primary key column with test UUIDs, to create a webhook signing secret, or to set a session secret in an .env file. For example, a 64-character Hex Token gives 256 bits, a common size for HMAC secrets. Note that an "API Key" here is only a random string in that format: it does nothing until the service you are building stores it and checks it. For human-friendly passwords with a strength meter, use the Password Generator; to encode existing text as Base64, use the Base64 Encoder/Decoder.

How to use the Random Token Generator

  1. 1

    Choose a token type

    Click UUID v4, Hex Token, Base64 Token, Alphanumeric, API Key or Secure Password.

  2. 2

    Set length and count

    For hex, Base64, alphanumeric and password tokens enter a Length from 4 to 256 characters. Enter a Count from 1 to 50.

  3. 3

    Generate

    Press Generate. Each press produces a fresh, independent set.

  4. 4

    Copy

    Use the copy icon next to a token, or Copy All to copy the whole list with one token per line.

What it can do

Standard UUID v4

Uses crypto.randomUUID() or an RFC 4122 version 4 fallback built from crypto.getRandomValues.

Six formats

UUID, hex, Base64, alphanumeric, sk_-prefixed key and password-style tokens.

No modulo bias

Character-based tokens use rejection sampling, so every allowed character is equally likely.

Batch output

Up to 50 tokens per click, with one-click copying of a single token or the whole list.

Limitations

  • Base64 tokens use the standard alphabet with + and /. If the token goes into a URL, choose Hex or Alphanumeric, or replace those two characters yourself.
  • The sk_ prefix of the API Key type is fixed and the key length is always 32 characters after it; use the Random String Generator for other prefixes.
  • Only UUID version 4 is offered, not time-ordered versions such as v1 or v7.
  • Tokens are not saved anywhere; copy them before you leave the page.

Privacy

Tokens are generated in your browser with the Web Crypto API and are never sent to FlexyPdf's servers.

Frequently asked questions

Is a UUID the same as a GUID?

Yes, GUID is Microsoft's name for the same 128-bit identifier format. A UUID v4 generated here can be used wherever a random GUID is expected.

Can two generated UUIDs be the same?

In theory yes, in practice no. A v4 UUID has 122 random bits, so the chance of a repeat is negligible even across billions of IDs, which is why databases use them as keys.

How long should a secret token be?

128 bits (32 hex characters) is a common minimum for session or API secrets, and 256 bits (64 hex characters) is often used for signing keys. Follow the length your framework or service documents.

Why does the Base64 token not end with = signs?

Padding only matters when Base64 encodes existing data. These tokens are random characters from the Base64 alphabet, cut to the length you asked for, so no padding is needed.

Ratings & Reviews

—
No ratings yet
5
0
4
0
3
0
2
0
1
0

Rate Random Token Generator

Help others by sharing your experience. Your rating is shown without your name.

0/600